Source Code Analysis: Exobot
ID: fd72d176-8b4a-5fa4-9703-7377e06a4c32
STIX ID: report--fd72d176-8b4a-5fa4-9703-7377e06a4c32
Feed Name: WatchGuard Secplicity Blog
This report details a hands‑on analysis of the leaked Exobot v2 source code, an Android banking trojan offered as a malware‑as‑a‑service. It walks through the malware ecosystem (exo/loader/socks), backend and frontend server setup, SQL schemas and multi‑tenant customer/admin panels, and highlights capabilities including overlay credential theft, device admin abuse to disable security, and SOCKS proxying via infected devices — demonstrating a sophisticated, scalable platform that lowers the technical barrier for attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
