Threats Tagged 'banking malware'
View all threats tagged with 'banking malware'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'banking malware'
Click on any threat for detailed analysis and mitigation recommendations
The Boto Cor-de-Rosa campaign reveals Astaroth's new strategy of exploiting WhatsApp Web for propagation. This Brazilian banking malware now uses a Python-based worm module to retrieve victims' WhatsApp contact lists and automatically send malicious messages, expanding its infection reach. The attack begins with a malicious ZIP file sent via WhatsApp, containing a Visual Basic script that downloads additional components. The malware then operates two parallel modules: a propagation module for spreading through WhatsApp contacts, and a banking module for credential stealing. This campaign demonstrates Astaroth's evolution, combining traditional malware techniques with sophisticated social engineering and multi-platform propagation, primarily targeting Brazilian users. Join the discussion | AlienVault OTX General | 01/08/2026, 18:12:03 UTC Added: 01/09/2026, 09:26:35 UTC |
Albiriox is a newly identified Android banking malware family that enables cybercriminals to remotely control infected devices and conduct financial fraud. It operates as Malware-as-a-Service (MaaS), featuring modular components such as loaders, command modules, and control panels designed specifically for targeting banking, fintech, payment, and cryptocurrency applications. Distributed via fake apps and social engineering, it mimics legitimate brands and app stores to deceive users. The malware abuses Android accessibility features and employs black-screen masking to hide malicious activity. Notably, it can bypass multi-factor authentication and device fingerprinting, increasing its effectiveness. Although currently rated medium severity, its capabilities pose significant risks to user confidentiality and financial integrity. European organizations with mobile banking users are at risk, especially in countries with high Android adoption and fintech usage. Mitigation requires verifying app sources, maintaining updated devices, deploying advanced anti-malware solutions, and educating users about social engineering tactics. Join the discussion | AlienVault OTX General | 12/03/2025, 20:19:08 UTC Added: 12/04/2025, 14:44:50 UTC |
A new Android Trojan masquerades as legitimate news reader or digital ID apps, stealthily stealing sensitive data by exploiting Android Accessibility Services and overlay features. It primarily targets banking and cryptocurrency applications by overlaying fake login screens to capture credentials. The malware operates silently in the background, connects to a remote command center for updates and cleanup, and has been observed mainly in Southeast Asia. Although no CVE or known exploits in the wild are reported, the malware's capabilities pose significant risks to user confidentiality and financial security. This threat highlights the importance of enhanced mobile security and user vigilance against fake apps and overlay attacks. Join the discussion | AlienVault OTX General | 11/05/2025, 12:36:23 UTC Added: 11/05/2025, 21:32:54 UTC |
A new Android Trojan named Datzbro has been discovered targeting seniors through fake Facebook groups promoting travel and social activities. The malware, which combines spyware and banking Trojan capabilities, is distributed via malicious APKs disguised as community apps. Datzbro features remote access, screen sharing, black overlay attacks, and keylogging, allowing attackers to perform financial fraud. It specifically targets banking and crypto-related apps, stealing credentials and sensitive information. The malware's origin appears to be Chinese-speaking developers, and its command-and-control application has been leaked, potentially making it a global threat. The campaign demonstrates the evolving sophistication of mobile threats, blending social engineering with advanced technical capabilities. Join the discussion | AlienVault OTX General | 09/30/2025, 12:03:47 UTC Added: 09/30/2025, 19:58:29 UTC |
Showing 1 to 4 of 4 results