logo

Android Banking Trojan Antidot Disguised as Google Play Update

ID: e71f5ebe-80b6-5b86-a2f6-acb6fd2445ac

STIX ID: report--e71f5ebe-80b6-5b86-a2f6-acb6fd2445ac

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-05-20

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

Cyble researchers observed a new Android banking Trojan named Antidot that impersonates Google Play update screens in multiple languages to perform overlay attacks and keylogging. After obtaining Accessibility permissions it registers with a WebSocket-based C2, sends installed-app lists to identify targets, displays HTML overlay phishing pages, exfiltrates credentials, collects SMS, issues USSD requests, and uses MediaProjection to enable VNC remote control—enabling full fraud chains; Google notes Play Protect can block known variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.