Remo Android Trojan Targets 50+ Banking Apps & Wallets
ID: 01bf2cea-7db6-5af7-88c4-6fae8793b5d6
STIX ID: report--01bf2cea-7db6-5af7-88c4-6fae8793b5d6
Feed Name: Cyble Blog
Threat Score
The report analyzes the Remo Android Banking Trojan distributed through Binance-impersonating phishing websites and additional fronts, which targets over 50 banking and cryptocurrency wallet applications across Thailand, Vietnam, and Indonesia by abusing Android Accessibility to capture screen text, keystrokes, and clipboard contents; it includes technical analysis, C2 details (https://vnoffs.cyou:8081), IOCs, low detection observations, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
