logo

Rise of Banking Trojan Dropper in Google Play

ID: c070b934-b1a7-57a8-8643-8c27d36b8590

STIX ID: report--c070b934-b1a7-57a8-8643-8c27d36b8590

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz discovered the Xenomorph banking trojan hidden inside Google Play apps (notably “Todo:Day manager”), which downloads malicious payloads from GitHub/Firebase, escalates to device-admin to block uninstall, intercepts SMS/notifications, and uses overlays to steal banking credentials and MFA codes; the report includes IoCs (package names, MD5s) and C2 infrastructure (GitHub links, Telegram-hosted RC4-encoded C2, and gogoanalytics domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.