logo

OverlayPhantom Android Banking Trojan Targets 180+ Financial Apps Across 10 Countries

ID: b1713b6e-79b0-5a34-bcf9-6a0ca3d35d26

STIX ID: report--b1713b6e-79b0-5a34-bcf9-6a0ca3d35d26

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-05-27

Date Updated: 2026-07-20

Author: Ashish Khaitan

...
...

OverlayPhantom is a sophisticated Android banking trojan active since May 2025 that spreads via malicious APKs impersonating trusted government and consumer apps; it abuses Android Accessibility Service to maintain persistent control, deploys visually convincing WebView phishing overlays to harvest credentials, and supports real-time screen streaming and over 30 remote commands to facilitate large-scale financial fraud across at least 10 countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.