Hook Android Trojan Now Delivers Ransomware-Style Attacks
ID: 1ea1cb12-19ea-57d8-99dd-6a4106c22b69
STIX ID: report--1ea1cb12-19ea-57d8-99dd-6a4106c22b69
Feed Name: Dark Reading
Date Published: 2025-08-26
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Zimperium warns of an evolved Hook Android banking Trojan variant that now includes ransomware-style full-screen device-lock overlays, fake NFC and payment-scraping overlays, lock-screen bypass tricks, transparent overlays to capture gestures, screen-streaming for real-time monitoring, and 107 remote commands; attackers are distributing malicious APKs via GitHub alongside traditional phishing, prompting recommendations to include mobile devices in enterprise endpoint defenses and to use on-device detection and behavior analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
