logo

GMBot: new ways of phishing data from mobile web browsers

ID: eb67e151-6bc8-5a4f-9083-0b49c156f552

STIX ID: report--eb67e151-6bc8-5a4f-9083-0b49c156f552

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2016-05-16

Date Updated: 2026-04-19

Author: Malgorzata Debska

...
...

**Executive Summary:** GMBot (slempo) is an Android banking trojan that presents fake overlay windows over banking apps and mobile browsers to phish credentials, exfiltrating stolen data (credentials, SMS, browser history, installed apps, etc.) to a C2 via HTTP; the report documents distribution via fake video/Flash player apps, required device administrator privileges, multiple additional malicious capabilities, prevalence in several countries, and provides indicators (SHA-256 and MD5 hashes) and remediation options (factory reset or ADB removal).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.