logo

Fake Document Manager App Downloading Hydra Banking Trojan

ID: 5f8aefa7-bb56-530f-b7b1-96c1edb9c9e1

STIX ID: report--5f8aefa7-bb56-530f-b7b1-96c1edb9c9e1

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-11-26

Date Updated: 2026-07-16

...
...

Cyble Research Labs discovered a malicious Android app on the Google Play Store masquerading as a "Document Manager" that acts as a hostile downloader for Hydra banking-trojan variants. The analysis provides APK metadata and hashes, describes a social-engineered fake update flow that requests INSTALL_PACKAGES and Accessibility permissions, documents C2/TOR communications and packed payloads, lists IOCs (hashes and URLs), and maps observed behaviors to MITRE ATT&CK techniques; the app reportedly achieved over 10,000 downloads and can steal SMS/OTP, contacts, cookies, and abuse Accessibility to prevent removal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.