Threats Tagged 'android banking trojan'
View all threats tagged with 'android banking trojan'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'android banking trojan'
Click on any threat for detailed analysis and mitigation recommendations
Gigabud is an Android remote access banking trojan active since 2022, attributed to GoldFactory group, targeting victims across Southeast Asia, South Asia, Middle East, Africa and Latin America. The malware now utilizes Vwork, a weaponized fork of the open-source app cloning application Shelter, to evade detection by creating isolated work profiles. After initial Gigabud infection, Vwork is installed to clone banking applications into the work profile, hiding malicious activity from signature-based detection in application security SDKs. Between February and July 2026, approximately 1,469 compromised devices and 1,281 potentially compromised logins were observed in Indonesia alone, with estimated losses of roughly $960,939. The infection chain involves social engineering through phishing sites delivering fake apps disguised as legitimate services, followed by credential theft through overlays and remote-controlled fraudulent transactions executed within cloned banking apps. Join the discussion | AlienVault OTX General | 09/09/2026, 15:55:37 UTC Added: 09/10/2026, 05:07:16 UTC |
ERMAC and HookBot are Android banking trojans derived from Cerberus source code. A leak of HookBot's builder, backend, and panel source code in August 2025 exposed default credentials and keys, allowing unauthorized operators to deploy malicious panels. HookBot extends ERMAC with VNC remote control and additional commands. The leaked source includes deployment tools such as a Docker stack and an IP-whitelist firewall that hides panels but leaves the builder port exposed. Operators target hundreds of apps across more than 40 countries, including banks and cryptocurrency wallets. Detection artifacts persist in obfuscation flags and favicons, but panel titles can be easily changed. Join the discussion | AlienVault OTX General | 08/25/2026, 16:29:33 UTC Added: 08/25/2026, 17:22:13 UTC |
A new NFC relay malware family called WindRelay has been discovered operating in combination with SpyNote RAT to enable sophisticated contactless payment fraud. The scheme uses live social engineering phone calls where fraudsters impersonate bank employees and guide victims to install personalized RAT malware labeled with the victim's own name. Once installed, the RAT enables silent deployment of WindRelay, which captures contactless payment card data via NFC when victims tap their cards to their phones. The captured data is relayed in real-time to fraudster-controlled terminals for immediate cash-out through physical purchases or ATM withdrawals. The operation employs dual monetization, combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026. Join the discussion | AlienVault OTX General | 08/12/2026, 12:12:48 UTC Added: 08/12/2026, 15:41:30 UTC |
An Android malware campaign masquerading as a bank KYC verification application targets users in India through WhatsApp distribution. The threat operates as a multi-stage dropper installing secondary payloads while establishing persistent command-and-control communication. It combines native code obfuscation, Firebase-based remote execution, VPN-based traffic manipulation, and WebView-based phishing to systematically harvest sensitive user data. The infection chain progresses through deceptive update screens, VPN activation, silent APK installation, and extensive permission abuse. The deployed payload enables SMS interception, call control, USSD execution, and structured credential theft through staged phishing interfaces mimicking legitimate banking workflows. Exfiltrated data is encrypted locally and transmitted to jsonapi.biz, while critical configuration values are hidden inside native libraries to hinder detection. Join the discussion | AlienVault OTX General | 04/29/2026, 09:43:48 UTC Added: 04/29/2026, 10:22:37 UTC |
Showing 1 to 4 of 4 results