logo

Source Code Analysis: Exobot

ID: fd72d176-8b4a-5fa4-9703-7377e06a4c32

STIX ID: report--fd72d176-8b4a-5fa4-9703-7377e06a4c32

Feed Name: WatchGuard Secplicity Blog

Threat Score
75/100

Date Published: 2019-04-12

Date Updated: 2026-05-01

Author: The Editor

...
...

This report details a hands‑on analysis of the leaked Exobot v2 source code, an Android banking trojan offered as a malware‑as‑a‑service. It walks through the malware ecosystem (exo/loader/socks), backend and frontend server setup, SQL schemas and multi‑tenant customer/admin panels, and highlights capabilities including overlay credential theft, device admin abuse to disable security, and SOCKS proxying via infected devices — demonstrating a sophisticated, scalable platform that lowers the technical barrier for attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.