logo

Deep-dive Analysis of S.O.V.A. Android Banking Trojan

ID: a784fd86-c1ad-5420-a90b-194c985d44ec

STIX ID: report--a784fd86-c1ad-5420-a90b-194c985d44ec

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-07-16

...
...

Cyble Research Labs analyzed S.O.V.A., a new Android banking trojan advertised on a darkweb forum that targets Android 7–11 (planned Android 12 support) and a wide list of banking/crypto apps. The report documents APK metadata (SHA256 hashes), dangerous permissions, manifest components (accessibility, notification listener, default SMS handling), detailed source-code behaviors (C2 commands, overlays/webview injections, cookie stealing, keylogging, SMS/clipboard monitoring), C2 URLs, and IoCs, and provides mitigation guidance and mappings to MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.