It’s similar to Lazarus’s Manuscrypt malware, but the new spyware is splattering itself onto government organizations and ICS in a non-Lazarus-like, untargeted wave of attacks.
https://threatpost.com/pseudomanuscrypt-mass-spyware-campaign/177097/
The banking trojan keeps switching up its lies, trying to fool Android users into clicking on a fake Flubot-deleting app or supposedly uploaded photos of recipients.
https://threatpost.com/flubot-malware-targets-androids-with-fake-security-updates/175276/