“Oscorp” is a new family of Android malware that abuses accessibility services in the device to hijack user credentials and record audio and video. The malware is called “Assistenzaclienti.apk” or “Customer Protection” and is distributed via a domain named “supportoapp[.]com” Once the access is provisioned, the malware exploits the permissions to log keystrokes, uninstall apps on the device, make calls, send SMS messages, steal cryptocurrency by redirecting payments made via the Bitcoin Wallet app.
Source: https://thehackernews.com/2021/01/italy-cert-warns-of-new-credential.html