GMBot: new ways of phishing data from mobile web browsers
ID: eb67e151-6bc8-5a4f-9083-0b49c156f552
STIX ID: report--eb67e151-6bc8-5a4f-9083-0b49c156f552
Feed Name: CERT Polska
**Executive Summary:** GMBot (slempo) is an Android banking trojan that presents fake overlay windows over banking apps and mobile browsers to phish credentials, exfiltrating stolen data (credentials, SMS, browser history, installed apps, etc.) to a C2 via HTTP; the report documents distribution via fake video/Flash player apps, required device administrator privileges, multiple additional malicious capabilities, prevalence in several countries, and provides indicators (SHA-256 and MD5 hashes) and remediation options (factory reset or ADB removal).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
