logo

On Google Play, Joker, Facestealer, & Coper Banking Malware

ID: 926e5644-5541-5236-a4e3-a9fbc3d28dfc

STIX ID: report--926e5644-5541-5236-a4e3-a9fbc3d28dfc

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-10-10

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz identified multiple malicious Android apps on Google Play distributing Joker (SMS/contact theft and premium-service fraud), Facestealer (fake Facebook WebView credential/token theft), and Coper (banking trojan with remote-control, SMS/USSD abuse and keylogging). The report includes technical analysis of how payloads are hidden and decrypted (asset files, native .so loaders, AES/RC4/ElGamal/DES/XOR obfuscation), examples of compromised app package names and a SHA256 sample, active C2 domains and URLs, and recommended user and enterprise mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.