OverlayPhantom Android Banking Trojan Targets 180+ Financial Apps Across 10 Countries
ID: b1713b6e-79b0-5a34-bcf9-6a0ca3d35d26
STIX ID: report--b1713b6e-79b0-5a34-bcf9-6a0ca3d35d26
Feed Name: The Cyber Express
Threat Score
OverlayPhantom is a sophisticated Android banking trojan active since May 2025 that spreads via malicious APKs impersonating trusted government and consumer apps; it abuses Android Accessibility Service to maintain persistent control, deploys visually convincing WebView phishing overlays to harvest credentials, and supports real-time screen streaming and over 30 remote commands to facilitate large-scale financial fraud across at least 10 countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
