logo

Bad Behaviour: How to detect banking trojans

ID: 2d6991ee-59b7-5c5f-8163-ae78aeac7733

STIX ID: report--2d6991ee-59b7-5c5f-8163-ae78aeac7733

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2023-02-20

Date Updated: 2026-04-27

...
...

This Group-IB report analyzes the Godfather Android banking Trojan (a modern Anubis variant) that targets customers of ~400 financial organizations across 16 countries, describing infection vectors (smishing, fake third-party apps), evasion techniques, malicious use of Android accessibility and sensitive permissions, observed behaviors (credential theft, SMS/OTP interception, automated currency conversion and deposits), and indicators such as the observed package name and permission set; it recommends behavior-based detection and fraud-intelligence countermeasures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.