GMBot: Android poor man’s “webinjects”
ID: da3eb94c-10d3-53c1-9a19-0c5cc7aef734
STIX ID: report--da3eb94c-10d3-53c1-9a19-0c5cc7aef734
Feed Name: CERT Polska
Threat Score
The report analyzes GMBot, a mobile banking trojan for Android that uses dynamic application overlays and WebView HTML snippets to impersonate banking and messaging apps, enabling credential and credit-card phishing as well as SMS-based OTP interception; it details targeted apps recovered from older source code, capabilities such as device-administrator abuse and locale checks to avoid Russian victims, and provides three sample hashes as indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
