logo

Brokewell: New Android Trojan Targeting Germany Users

ID: 6178a3ab-2c68-521a-85cb-7966cf8c90a8

STIX ID: report--6178a3ab-2c68-521a-85cb-7966cf8c90a8

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-12-04

Date Updated: 2026-07-16

...
...

CRIL identified a new Android banking Trojan called Brokewell distributed via a fake Chrome update site; the report attributes development to a developer known as “Baron Samedit,” describes a Gitea-hosted loader that installs the payload without external storage permissions, details extensive capabilities (overlay attacks, keylogging, cookie theft, screen/audio recording, automated gestures and permission abuses via the Accessibility service), documents active C2 infrastructure and ports, provides multiple IOCs (hashes, domains, URLs), and warns that the malware—currently focused on Germany—appears poised to evolve and expand.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.