BankBot & Friends: Phishing Mobile Customers Like You Soon
ID: 20cc6816-c905-5f18-819d-a53c6ceab814
STIX ID: report--20cc6816-c905-5f18-819d-a53c6ceab814
Feed Name: Zimperium Blog
This report describes BankBot-family Android banking trojans that are distributed via seemingly legitimate apps, enumerate installed banking apps, contact a C2 to retrieve overlay content, and display fake login screens over legitimate banking apps to phish credentials; the malware initially targeted ~20 apps, expanded to 150+ banks across 27 countries, and recent variants target Polish banks disguised as 'Crypto Monitor' and 'StorySaver'. It also notes detection capabilities provided by Zimperium's z9 and zIAP solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
