Emerging
Published Jun 25, 2026Updated Jun 25 Major3
85%
Cybercriminals Exploit Fuel Shortage with Malicious Android Apps in Russia
Cybercriminals have launched a coordinated attack on Russian drivers, distributing malicious Android apps disguised as fuel-finding services. Exploiting fuel shortages affecting multiple Russian regions, the campaign uses phishing websites and unverified APK downloads to steal personal data, hijack accounts, and harvest sensitive files from over 1,000 confirmed targets since mid-June.
Quick Facts
- Distribution of malicious Android applications disguised as fuel-finding services
- Creation of phishing websites imitating gas station services
- Direct APK file downloads bypassing official app stores
- Harvesting of personal documents, photos, videos, and contacts
- Hijacking of Telegram accounts via SMS code interception





Cybersecurity experts have identified a sophisticated campaign targeting Russian drivers with malicious Android applications disguised as fuel-finding services. Taking advantage of fuel availability concerns affecting several Russian regions, attackers have created phishing websites imitating gas station services and distributed malware under the guise of legitimate utility apps. Kaspersky Lab researchers found that over 1,000 users attempted to download such APK files directly from phishing sites since mid-June, bypassing official app stores — a significant indicator of broader exposure, as the actual number of potential victims may be substantially higher.
The malware campaign employs multiple deceptive tactics. One common scheme involves fake online fuel reservation services offering to sell 20 liters of petrol without queuing; users are prompted to enter SMS verification codes, which criminals then exploit to hijack Telegram accounts for further fraud or extortion. Another identified threat masquerades as a fuel-finding service called "Где бензин?" (Where is the gas?), which generates fake fuel availability data while distributing malicious APK files. Once installed, these applications request access to device location and files, enabling thieves to harvest documents, photos, videos, contacts, and personal data.
The timing of the attacks coincides with fuel access restrictions implemented across multiple Russian regions. Since late June, authorities in Crimea, Sevastopol, Adygea, Lipetsk, and Kurgan regions have imposed fuel sale limitations in response to heightened demand and supply concerns. Cybersecurity experts emphasize that attackers deliberately exploit such high-demand, high-anxiety situations to increase the likelihood of user compliance with download requests.
Security researchers from Kaspersky Lab and F6 stress the critical distinction between downloading apps from official platforms like RuStore and acquiring APK files from third-party sources. Official app stores include security vetting absent on phishing domains. The attackers capitalize on users' desire for legitimate fuel-finding tools and promise real-time information about petrol availability across the country, complete with filtering and bookmarking features — functionality that never materializes after installation. Experts recommend downloading applications exclusively from authorized vendors and exercising caution when granting file and location permissions.
Why This Matters
This campaign demonstrates how cybercriminals weaponize real-world crises to maximize user vulnerability. Russian drivers facing genuine fuel shortages are targeted with convincing fake apps, making this attack particularly effective. Understanding the tactics—phishing domains, APK sideloading, SMS code theft—helps users protect themselves and avoid account compromise during periods of high demand and anxiety.
Timeline & Sources
Jun 15, 2026
WireMalicious Android apps disguised as fuel-finding services begin distribution; first downloads recorded
Jun 21, 2026
WireCrimea and Sevastopol authorities announce fuel sale restrictions via SMS and cash limits; Head Sergey Aksyonov declares suspension of petrol sales at gas stations
Jun 25, 2026
WireVedomosti publishes report linking malware campaign to regional fuel restrictions
Jun 25, 2026
WireTelesputnik reports additional campaign details including fake fuel reservation and SMS interception schemes
Sources
- "Лаборатория Касперского" выявила шпионское приложение для Android для поиска топливаИнтерфаксMediaJun 25, 2026
- «Лаборатория Касперского» нашла шпионское «приложение для поиска топлива»ВедомостиMediaJun 25, 2026
- Киберпреступники атакуют российских водителей под видом сервисов поиска бензинаtelesputnik.MediaJun 25, 2026