logo

Dissection Of Zertsecurity - Banking Trojan.

ID: 1ebaba28-b545-52f6-a25d-11ad55903451

STIX ID: report--1ebaba28-b545-52f6-a25d-11ad55903451

Feed Name: Zscaler Security Research Blog

Threat Score
55/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zertsecurity is a simple Android banking Trojan targeting German users via phishing: it prompts victims for account numbers and PINs, encrypts and stores the credentials in cfg.txt, exfiltrates the file to a hardcoded C&C server, and accepts SMS-based commands (identified by the string '&Sign28tepXXX'). The malware uses AES and Base64 encoding and requests SMS receive permissions to enable remote control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.