logo

Aberebot-2.0 Malware Targets Social Media & Banks Globally

ID: 88b47167-f9fa-524b-8657-13b3b7aec665

STIX ID: report--88b47167-f9fa-524b-8657-13b3b7aec665

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-11-26

Date Updated: 2026-07-16

...
...

Aberebot v2.0 is an Android banking/infostealer malware analyzed in this report: it abuses Accessibility and notification-listener services to perform overlays, keylogging, SMS/clipboard/notification theft, file enumeration and exfiltration, and can inject values into banking/crypto apps; the sample (SHA256 ee20d6abcf...83f3) and distribution URL (https://itts.hr/FinaCertifikat/Fina.apk) plus a Telegram-based C2 (https://api.telegram.org/bot1962569196) are provided, and the malware targets ~230 apps across 22 countries with recommendations for prevention and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.