logo

New Hydra Trojan Targets European Banking Users

ID: 9a4d5c58-6b29-5c98-9cb3-e22596174f27

STIX ID: report--9a4d5c58-6b29-5c98-9cb3-e22596174f27

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-13

Date Updated: 2026-07-16

...
...

Cyble Research Labs analyzed a phishing campaign delivering a Hydra Android banking trojan impersonating the CommerzBank mobile app; the sample requests dangerous permissions (including Accessibility and Device Admin), hides malicious DEX code via a custom packer, and implements advanced features such as Accessibility-based remote-control (TeamViewer-like screencast), TOR-based C2 retrieval, SOCKS proxying, Play Protect disabling, SMS/contact exfiltration, and premium service fraud. The report includes APK metadata, manifest and source-code observations, execution behavior, C2/Ioc artefacts (SHA256 hashes, hosting IP, .onion proxy URL, and decoded C2 URL), mapped MITRE ATT&CK techniques, and recommended remediation steps (uninstall/factory reset, block IoCs, update AV/OS, use official stores and MFA).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.