logo

Gustuff: Weapon of Mass Infection

ID: 72404306-9339-559f-9b5e-2d090da7533e

STIX ID: report--72404306-9339-559f-9b5e-2d090da7533e

Feed Name: Group-IB Blog

Threat Score
80/100

Date Published: 2019-04-04

Date Updated: 2026-04-27

...
...

Group-IB's technical analysis of the Gustuff Android banking Trojan documents a sophisticated financial theft malware distributed via SMS-delivered APKs that targets >100 banking and crypto apps worldwide. Gustuff uses Android Accessibility Service for Automatic Transfer Systems (ATS) to auto-fill and execute illicit transactions, displays phishing push notifications, exfiltrates SMS/contacts/files, runs a SOCKS5 backconnect proxy, and accepts extensive JSON-formatted C2 commands (sample C2 IP observed: 88.99.171.105). The report details its configuration, command set, proxy/session logging, and provides detection/mitigation guidance for banks and end users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.