logo

SoumniBot: the new Android banker’s unique techniques

ID: 088ea9b4-e8e4-57cc-937c-9f258ec068ee

STIX ID: report--088ea9b4-e8e4-57cc-937c-9f258ec068ee

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-04-17

Date Updated: 2026-04-29

Author: Dmitry Kalinin

...
...

SoumniBot is an Android banking Trojan targeting Korean users that uses unconventional AndroidManifest obfuscation techniques (invalid ZIP compression method, incorrect manifest size with overlay, and overly long XML namespace names) to evade analysis and installation checks; it collects and exfiltrates sensitive data including SMS, contacts, media and Korean banking keys/certificates (NPKI/yessign), communicates with C2 via hardcoded mainsite and MQTT servers, and exposes multiple remote commands for data theft and device manipulation. Indicators include several MD5 hashes and C2 domains provided in the report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.