logo

Android Bankers: 4 Campaigns In A Row

ID: 4102681f-ba61-5267-b357-9dd7afb35e0f

STIX ID: report--4102681f-ba61-5267-b357-9dd7afb35e0f

Feed Name: Zimperium Blog

Threat Score
80/100

Date Published: 2026-04-16

Date Updated: 2026-05-01

...
...

**Executive Summary:** Zimperium zLabs identified four active Android banking trojan campaigns (RecruitRat, SaferRat, Astrinox, Massiv) targeting over 800 banking, cryptocurrency, and social media applications; the report details delivery via phishing/smishing and fake sites, multi-stage sideloading and Session Installer abuse, persistence through Accessibility Service exploitation and icon hiding, sophisticated evasion (ZIP tampering, reflection, encrypted payloads), real-time screen and keystroke exfiltration (MediaProjection, keylogging, overlays), C2 behaviors and MITRE ATT&CK mappings, and points to a repository containing IoCs and full command lists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.