logo

Banking Trojan Variant Spreading Through Android App

ID: 035c3ec8-e0a1-556e-967b-5f83762d0f82

STIX ID: report--035c3ec8-e0a1-556e-967b-5f83762d0f82

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-05-12

Date Updated: 2026-07-16

...
...

Cyble researchers analyzed an Android banking Trojan distributed via a fake app (package com.android.ktspo, main activity pkgflag.cocknut.yummy.MainActivity) that targets users in Korea; the malware requests extensive permissions, implements SMS capture, keylogging, audio recording, location tracking, call monitoring, process termination, and exfiltrates collected data to a Command-and-Control URL (http://103.147.12.89/api/interfaceA). The report provides static and dynamic findings, a SHA256 sample hash, IoCs, a mapping to MITRE ATT&CK mobile techniques, and actionable safety recommendations for users and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.