Drinik is an Android malware family that originated as an SMS-stealing threat and later evolved into an Android banking trojan focused on Indian taxpayers and customers of Indian banks. It has been active since at least 2016 and was observed re-emerging around 2021 with expanded credential-theft and surveillance functionality. Campaigns associated with Drinik have impersonated India’s Income Tax Department and used tax-themed lures to harvest banking and personal information.
Modern Drinik variants abuse Android Accessibility Service to obtain permissions, automate user-interface actions, capture keystrokes, initiate screen recording, and interfere with device protections. Reported capabilities include collecting SMS messages, stealing incoming SMS content, sending SMS messages from compromised devices, accessing call-log data, and reading from external storage. Drinik also exfiltrates stolen information to command-and-control infrastructure. More advanced variants have used WebView to display the legitimate Indian income tax portal inside the malicious application while overlaying or chaining phishing steps to capture identifiers, banking credentials, payment-card data, and PINs. Screen recording and keylogging have been used to capture sensitive input during these workflows.
Additional functionality observed in later variants includes abuse of Android call-screening features to suppress incoming calls without the user’s knowledge and use of cloud messaging for command handling. Drinik has also employed string encryption and runtime decryption to hinder analysis and evade detection. The malware is best characterized as a financially motivated Android banking trojan with phishing, credential theft, SMS interception, surveillance, and data-exfiltration capabilities, primarily targeting Indian financial users and tax-related workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan targeting Indian taxpayers. It impersonates the Indian Income Tax Department, abuses Accessibility Service, performs screen recording and keylogging, steals biometric PINs, banking credentials, SMS and personal/financial data, loads genuine tax portals in WebView, uses phishing pages for refund scams, receives commands via Firebase Cloud Messaging, and can suppress incoming calls via CallScreeningService.
Android malware that requests storage permissions to access device files.
Android malware that requests storage permissions to access device files.
Android malware that requests storage permissions enabling access to device files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.