Android Banking Trojan Antidot Disguised as Google Play Update
ID: e71f5ebe-80b6-5b86-a2f6-acb6fd2445ac
STIX ID: report--e71f5ebe-80b6-5b86-a2f6-acb6fd2445ac
Feed Name: Dark Reading
Cyble researchers observed a new Android banking Trojan named Antidot that impersonates Google Play update screens in multiple languages to perform overlay attacks and keylogging. After obtaining Accessibility permissions it registers with a WebSocket-based C2, sends installed-app lists to identify targets, displays HTML overlay phishing pages, exfiltrates credentials, collects SMS, issues USSD requests, and uses MediaProjection to enable VNC remote control—enabling full fraud chains; Google notes Play Protect can block known variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
