HookBot Malware’s Overlay Attacks To Impersonate As Popular Brands
ID: cb326b1e-3d13-578d-8d76-a25b3f6114ad
STIX ID: report--cb326b1e-3d13-578d-8d76-a25b3f6114ad
Feed Name: cybersecurityNews.com
Threat Score
NetCraft researchers describe HookBot, an evolving Android banking Trojan distributed via malicious apps on unofficial stores and Telegram that uses overlay attacks to impersonate trusted apps and steal credentials through keylogging, screen capture, and SMS interception; the malware features a builder tool for low-skill operators, obfuscation to hinder analysis, C2-driven HTML overlays for rapid updates, and worm-like propagation via automated WhatsApp messages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
