logo

Over 800 Android Apps Targeted in PIN-Stealing Trojan Campaign

ID: 6c39f889-7cda-5f18-b2a4-5be1094018c9

STIX ID: report--6c39f889-7cda-5f18-b2a4-5be1094018c9

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: Joseph Ofonagoro

...
...

### Executive summary Zimperium zLabs reports four parallel Android banking-trojan campaigns that together target over 800 banking, cryptocurrency, and social apps by abusing Accessibility Services and overlay permissions to capture PINs, deploy fake screens, monitor interactions, and persist on devices; infection vectors include phishing, homograph domains, and sideloaded fake or cloned apps using the Native Session Installation API to bypass restrictions. The malware families use multi-stage droppers, non-interactive overlays to hide permission grants, and uninstall-resistance techniques to enable real-time credential and 2FA theft and potential account or device takeover; recommended mitigations are avoiding sideloading, reviewing/revoking Accessibility and overlay permissions, and using mobile anti-malware solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.