logo

BRATA Keeps Sneaking into Google Play, Now Targeting USA and Spain

ID: e6b299ab-4f9b-51ff-afbb-989cd22c5db5

STIX ID: report--e6b299ab-4f9b-51ff-afbb-989cd22c5db5

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2021-04-12

Date Updated: 2026-04-28

Author: Fernando Ruiz

...
...

McAfee Mobile Research documents BRATA, an Android banking trojan distributed via Google Play that poses as security scanners to trick users into granting accessibility permissions; once installed it can capture PINs, keylog, record screens, display phishing pages for financial apps (targets in Brazil, Spain, USA), and uses obfuscation, remote payloads, and commercial packers to evade analysis. The report provides IoCs (SHA256 hashes, package names, malicious domains), details of capabilities and attack flow, and recommended defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.