logo

Analysis of a Polish BankBot

ID: d4e36c96-4820-55da-8a19-3754c94e28ec

STIX ID: report--d4e36c96-4820-55da-8a19-3754c94e28ec

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2018-01-16

Date Updated: 2026-04-19

Author: Agnieszka Bielec

...
...

This report analyzes a BankBot variant targeting Polish Android users, distributed through malicious apps on Google Play (notably "Crypto Monitor", "StorySaver" and "Cryptocurrencies Market Prices"). It documents the trojan's capabilities—embedding phishing pages in WebView and harvesting credentials via hooked onJsPrompt, intercepting and exfiltrating SMS (including bank auth codes), using Firebase for messaging/tokens while sending stolen data to an external C2, lists targeted Polish banks and requested permissions, and provides IoCs and hashes for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.