OverlayPhantom-android-banking-trojan-hiding In Plain Sight
ID: e101a235-ea1e-5f4c-b551-6d724875b006
STIX ID: report--e101a235-ea1e-5f4c-b551-6d724875b006
Feed Name: Cyble Blog
**Executive Summary:** OverlayPhantom is a sophisticated Android banking trojan actively distributed via phishing URLs impersonating high-trust apps (e.g., ID Austria, TikTok). It uses a dropper to trick users into enabling Accessibility Service, hides as Google Play Services, deploys HTML WebView overlays to harvest credentials from over 180 targeted banking/crypto apps across 10 countries, and provides over 30 remote commands plus JPEG-based real-time screen streaming to a multi-port C2 infrastructure (199.217.99.122 ports 9090–9092).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
