logo

Vultur Android Banking Trojan Returns with Upgraded Remote Control Capabilities

ID: 399ed14f-5bfe-5950-b156-2c0d9f252320

STIX ID: report--399ed14f-5bfe-5950-b156-2c0d9f252320

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes the resurgence of the Android banking trojan Vultur, which now uses encrypted C2 communications, multiple on-the-fly decrypted payloads, enhanced anti-analysis and evasion techniques, and expanded remote-control capabilities via Android accessibility services; it is distributed through trojanized Play Store dropper apps and telephone-oriented attack delivery (TOAD). The article contextualizes Vultur alongside other active Android banking threats (Octo/Coper and MaaS campaigns), cites infection scale for related campaigns, and notes mitigations such as Google Play Protect.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.