Trojan-as-a-Service Hits Euro Banks, Crypto Exchanges
ID: 4a90c87d-522e-5592-bc05-5f641a6e7743
STIX ID: report--4a90c87d-522e-5592-bc05-5f641a6e7743
Feed Name: Dark Reading
Date Published: 2024-12-05
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
A new Android banking RAT called DroidBot has been active since mid-2024 and is being offered as Malware-as-a-Service, used by multiple affiliates in dozens of attacks across France, Italy, Portugal, and Spain; it combines keylogging, SMS interception, screenshot capture, accessibility-service abuse, and dual-channel MQTT/HTTPS communications, and is actively developed with signs of expansion toward Spanish-speaking regions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
