logo

Sophisticated Android Banking Trojan Threat Evades Detection via High-Trust Lures

ID: 6ca43fb6-7fbb-5652-a313-fe0490c4c4c7

STIX ID: report--6ca43fb6-7fbb-5652-a313-fe0490c4c4c7

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Ddos

...
...

Researchers identified a large-scale Android banking trojan campaign that spreads via fake app packages and deceptive update prompts to obtain persistent Accessibility and MediaProjection privileges. The malware, reported to target 180+ banking, finance, and cryptocurrency apps across 10 countries, injects WebView-based phishing overlays to harvest credentials, streams the device screen to capture verification codes, and exposes a multi-port command-and-control infrastructure (ports 9090–9092) enabling extensive remote control and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.