09 Ajina

Ajina

Region
Central Asia
Industries
Banking
First seen
May 2024
Cybercrime
Android banker malware targeting everyday users
Heritage
Likely part of a large underground network
Categorizations
Mobile banking malware
About

This rapidly growing group of Masked Actors are part of an affiliation network, suggesting a bigger organized cybercrime operation. Ajina focuses on large-scale financial fraud, targeting banking apps. Group-IB identified this specialized group following an investigation in May 2024.

Learn more about Ajina from Group-IB’s research
Victims

Our investigation analyzed over 1,400 unique Android malware samples, suggesting a significant number of affected users. Ajina’s victims are everyday users of banking and payment phone apps. Victims are primarily in Central Asia, but the campaign has expanded globally.

What we know about Ajina members

Our analysis of file names, sample distribution methods, and other activities shows the attackers seem familiar with Central Asian culture, suggesting local ties. Members operate through a network of affiliates, each distributing malware. Use of Telegram channels indicates a well-coordinated effort.

Motivations
Financial gain via theft of banking credentials and interception of two-factor authentication.
Top 10 Masked Actors for 2025
RansomHub
#1
GoldFactory
#2
Lazarus
#3
DragonForce
#4
Oilrig
#5
MuddyWater
#6
Brain Cipher
#7
Boolka
#8
Ajina
#9
Team TNT
#10