BlankBot: A New Android Banking Trojan Cannot Evade on Device Machine Learning Protection
ID: 9a626189-718f-5047-98e7-bc39641cc01b
STIX ID: report--9a626189-718f-5047-98e7-bc39641cc01b
Feed Name: Zimperium Blog
BlankBot is a newly discovered Android banking trojan that targets primarily Turkish users and exfiltrates banking credentials by abusing MediaProjection-based screen recording, accessibility-based keylogging, remote-control commands from a C2 server, and custom overlay injections. Zimperium identified nine samples in July 2024 and reports that its MTD and MAPS products detect these samples with high confidence, highlighting both the malware's advanced capabilities and the vendor's detection coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
