logo

BlankBot: A New Android Banking Trojan Cannot Evade on Device Machine Learning Protection

ID: 9a626189-718f-5047-98e7-bc39641cc01b

STIX ID: report--9a626189-718f-5047-98e7-bc39641cc01b

Feed Name: Zimperium Blog

Threat Score
72/100

Date Published: 2024-08-12

Date Updated: 2026-05-01

...
...

BlankBot is a newly discovered Android banking trojan that targets primarily Turkish users and exfiltrates banking credentials by abusing MediaProjection-based screen recording, accessibility-based keylogging, remote-control commands from a C2 server, and custom overlay injections. Zimperium identified nine samples in July 2024 and reports that its MTD and MAPS products detect these samples with high confidence, highlighting both the malware's advanced capabilities and the vendor's detection coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.