BlankBot Trojan Targets Turkish Android Users
ID: f10b3997-395d-5c4f-b988-9dc0024242e0
STIX ID: report--f10b3997-395d-5c4f-b988-9dc0024242e0
Feed Name: Dark Reading
BlankBot is a newly identified Android banking trojan targeting Turkish-language users that can record screens (via MediaProjection), capture keystrokes (including via a custom keyboard), create phishing overlays using open-source libraries, collect contacts/SMS/installed apps, and remotely control devices through accessibility gestures; it shows active development, multiple variants, anti-analysis features, and low detection rates on VirusTotal, and is assessed as being used for account takeover and financial fraud rather than espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
