logo

Hook Android Trojan Now Delivers Ransomware-Style Attacks

ID: 1ea1cb12-19ea-57d8-99dd-6a4106c22b69

STIX ID: report--1ea1cb12-19ea-57d8-99dd-6a4106c22b69

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-08-26

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Zimperium warns of an evolved Hook Android banking Trojan variant that now includes ransomware-style full-screen device-lock overlays, fake NFC and payment-scraping overlays, lock-screen bypass tricks, transparent overlays to capture gestures, screen-streaming for real-time monitoring, and 107 remote commands; attackers are distributing malicious APKs via GitHub alongside traditional phishing, prompting recommendations to include mobile devices in enterprise endpoint defenses and to use on-device detection and behavior analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.