logo

SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store

ID: f3775dfb-664b-5f7c-a0f2-952efeaa67a2

STIX ID: report--f3775dfb-664b-5f7c-a0f2-952efeaa67a2

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2022-03-03

Date Updated: 2026-04-27

Author: Joost Jansen

...
...

SharkBot is an Android banking malware distributed as a fake antivirus via the Google Play Store that abuses Accessibility Services and a novel Automatic Transfer System (ATS) to automate fraudulent transfers and bypass MFA; the report provides technical analysis of its C2 protocol (RC4+RSA), DGA, command set, propagation via notification auto-reply, sample hashes, C2 domains and public keys, and notes observed distribution and dropper behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.