Skip to main content

Threats Tagged 'overlay attacks'

View all threats tagged with 'overlay attacks'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: overlay attacks

Threats Tagged 'overlay attacks'

Click on any threat for detailed analysis and mitigation recommendations

ERMAC and HookBot are two branches of one Android banking trojan sold as a service, forking from shared code originating with Cerberus. A copy of the builder, Laravel backend, and React panel leaked in August 2025, enabling unrelated operators to deploy panels with default credentials and keys still in place. The lineage runs Cerberus to ERMAC to Hook, confirmed through source code analysis showing identical database migrations and network protocol structures. HookBot added VNC remote control and 38 new commands while maintaining ERMAC's core. The leaked source includes a Docker stack, Obfuscapk builder, and IP-whitelist firewall that hides panels but leaves the builder port exposed. Operators target 484 apps across 40+ countries including Japanese banks, Brazilian financial institutions, Turkish banks, and cryptocurrency wallets. Detection artifacts survive in builder obfuscator flags and favicons, while panel titles remain easily changed.

Join the discussion

A malicious campaign was detected impersonating an Italian banking brand through a fraudulent domain offering fake financial rewards for installing a mobile application. Users are redirected to a Telegram bot that distributes a malicious Android APK outside official app stores. The APK functions as a dropper containing an embedded second-stage payload identified as Albiriox, an Android banking Remote Access Trojan. This payload exploits Accessibility services, implements overlay attacks, intercepts SMS messages, captures credentials, and enables remote device control through a custom TCP-based command-and-control protocol. The infrastructure uses domain impersonation and social engineering with financial incentives to distribute the malware. Communication occurs via raw TCP sockets to endpoints on ports 5555 and 5552, with JSON messages framed using big-endian length prefixes. Attribution to Albiriox is supported by protocol similarities, behavioral patterns, and comparison with known Albiriox samples.

Join the discussion

A newly identified Android banking trojan named Rokarolla has been discovered, distributed through malicious websites masquerading as popular applications like TikTok or Google Chrome. The malware targets 217 distinct cryptocurrency and banking applications using 137 sophisticated commands for device control. Capabilities include harvesting lock screen credentials, exfiltrating contact lists and SMS data, deploying keyloggers, blocking calls, creating fraudulent screen overlays, and disabling Google Play Protect. The infection begins with a dropper impersonating Google Play Protect that installs a secondary payload. Rokarolla communicates with C2 infrastructure via HTTPS, uses overlays to steal banking credentials and device unlock patterns, silently monitors WhatsApp contacts, hijacks SMS and calls, manipulates clipboard content for cryptocurrency theft, and employs snapshot-based screen surveillance. It maintains persistence by hiding its icon, muting device audio, and keeping screens active indefinitely.

Join the discussion
0

Perseus is a new Android threat that builds upon earlier malware families like Cerberus and Phoenix. It enables real-time monitoring and interaction with infected devices through Accessibility-based remote sessions, allowing full Device Takeover. The malware focuses on extracting high-value personal information, including monitoring user notes. It employs strong anti-analysis measures to evade detection. Perseus is primarily distributed through IPTV applications, targeting users in Turkey and Italy. Its capabilities include overlay attacks, keylogging, and systematic exploration of note-taking apps. The malware performs extensive environment checks to detect analysis conditions and assess device risk. Perseus represents the ongoing evolution of mobile malware, adapting to remain effective in an increasingly secure mobile environment.

Join the discussion

A new Android banking Trojan named Massiv has been discovered, posing a significant threat to mobile banking users. This malware allows remote control of infected devices and enables Device Takeover attacks, leading to fraudulent transactions from victims' accounts. Massiv is distributed through side-loading, often masquerading as IPTV applications. It features overlay functionality, keylogging, and SMS/Push message interception to steal sensitive data. The malware has targeted government applications and digital identity wallets, particularly in Portugal. Massiv supports screen streaming and UI-tree modes for remote control, bypassing screen capture protections. The trend of malware masquerading as IPTV apps is increasing, exploiting users' willingness to install from unofficial sources.

Join the discussion

Albiriox is a newly discovered Android RAT malware offered as Malware-as-a-Service, primarily targeting financial and cryptocurrency applications globally. It uses a sophisticated two-stage deployment involving dropper apps and packing to evade detection. The malware enables remote control of infected devices via VNC-based access and overlay attacks, allowing real-time interaction and unauthorized operations such as screen manipulation and device takeover. It targets over 400 financial and crypto wallet apps, facilitating on-device fraud while remaining stealthy. The MaaS model and ongoing development indicate potential rapid spread among cybercriminals. Although no known exploits in the wild are reported yet, its advanced capabilities pose a significant threat to mobile users, especially in finance sectors. The malware is linked to Russian-speaking threat actors and uses multiple fake domains for distribution. European organizations with mobile banking and crypto wallet users are at risk, particularly in countries with high Android usage and financial sector prominence. Mitigation requires targeted detection of dropper apps, user education on app sources, and enhanced mobile endpoint protection. Given its impact on confidentiality, integrity, and availability with ease of exploitation and no user interaction needed post-installation, the threat severity is assessed as high.

Join the discussion

Android/BankBot-YNRK is a sophisticated mobile banking Trojan targeting Android devices, specifically aiming at financial and cryptocurrency applications. It abuses Android accessibility services to gain elevated privileges, enabling it to automate UI interactions and extract sensitive user data. The malware can masquerade as legitimate apps, suppress audio notifications to avoid user detection, and perform unauthorized operations such as credential theft and fraudulent transactions. It maintains persistence on infected devices and communicates with command-and-control (C2) servers to receive remote commands and exfiltrate data. Although no known exploits are reported in the wild, the trojan represents a significant threat to Android users, especially those engaged in mobile banking and cryptocurrency activities. The malware’s complexity and stealth capabilities increase the risk of financial loss and privacy breaches. European organizations with employees or customers using Android banking or crypto apps are at risk, particularly in countries with high Android market share and digital banking adoption. Mitigation requires targeted measures including restricting accessibility service permissions, monitoring network traffic for suspicious domains, and educating users on app installation risks.

Join the discussion

A new Android banking trojan named RatOn has emerged, combining NFC relay attacks with remote access and automated transfer capabilities. Discovered by analysts monitoring the NFSkate threat group, RatOn targets cryptocurrency wallets and banking applications, particularly in the Czech Republic and Slovakia. The malware is distributed through adult-themed websites and employs a multi-stage infection process. RatOn features overlay attacks, automated money transfers, and cryptocurrency wallet takeovers. It demonstrates sophisticated capabilities, including screen casting, PIN interception, and extensive bot commands. The trojan's evolution from a basic NFC relay tool to a complex RAT with ATS functionality makes it a significant threat in the mobile malware landscape.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: overlay attacks
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses