logo

OverlayPhantom-android-banking-trojan-hiding In Plain Sight

ID: e101a235-ea1e-5f4c-b551-6d724875b006

STIX ID: report--e101a235-ea1e-5f4c-b551-6d724875b006

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2026-05-27

Date Updated: 2026-07-17

...
...

**Executive Summary:** OverlayPhantom is a sophisticated Android banking trojan actively distributed via phishing URLs impersonating high-trust apps (e.g., ID Austria, TikTok). It uses a dropper to trick users into enabling Accessibility Service, hides as Google Play Services, deploys HTML WebView overlays to harvest credentials from over 180 targeted banking/crypto apps across 10 countries, and provides over 30 remote commands plus JPEG-based real-time screen streaming to a multi-port C2 infrastructure (199.217.99.122 ports 9090–9092).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.