logo

Zscaler Protections Against Flubot Banking Malware

ID: dff4d2a9-a586-5e1c-af8a-77f554e01767

STIX ID: report--dff4d2a9-a586-5e1c-af8a-77f554e01767

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes the widespread Flubot Android banking malware campaign that uses SMS-based smishing to trick users into installing fake delivery or Chrome apps; once installed it harvests SMS and contacts, uses Accessibility Services to disable protections and display fake overlays to steal banking credentials and credit-card data, spreads via the victim's contacts, and uses DGA/RSA-protected C2 communications; the report also references vendor analysis and Zscaler detection coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.