logo

Flubot: the evolution of a notorious Android Banking Malware

ID: 1d7828e9-a430-5474-8ce6-ec3384b947cb

STIX ID: report--1d7828e9-a430-5474-8ce6-ec3384b947cb

Feed Name: Fox-IT blog

Threat Score
78/100

Date Published: 2022-06-29

Date Updated: 2026-04-27

Author: Global Threat Intelligence

...
...

This report analyzes Flubot, a widespread Android banking malware that used smishing and infected devices as a distribution botnet to steal credentials and session cookies via accessibility abuse, web injections, and WebView cookie capture; it documents version-by-version technical changes (DGA seeds, DoH, RC4, DNS TXT tunneling), operational campaigns across many countries, sample hashes, and the eventual Europol-enabled disruption of its C2 infrastructure while noting the potential for reconstitution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.