logo

GMBot: Android poor man’s “webinjects”

ID: da3eb94c-10d3-53c1-9a19-0c5cc7aef734

STIX ID: report--da3eb94c-10d3-53c1-9a19-0c5cc7aef734

Feed Name: CERT Polska

Threat Score
72/100

Date Published: 2015-10-02

Date Updated: 2026-04-19

Author: Łukasz Siewierski

...
...

The report analyzes GMBot, a mobile banking trojan for Android that uses dynamic application overlays and WebView HTML snippets to impersonate banking and messaging apps, enabling credential and credit-card phishing as well as SMS-based OTP interception; it details targeted apps recovered from older source code, capabilities such as device-administrator abuse and locale checks to avoid Russian victims, and provides three sample hashes as indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.