DoubleTrouble is an Android banking trojan tracked in 2025 and reported by Zimperium as targeting European banks. Available reporting describes it as mobile banking malware used to distribute malicious Android APKs and as part of the broader rise in Android banking malware affecting the financial sector. DoubleTrouble was initially spread through phishing sites, and researchers observed in July 2025 that it was also being distributed through Discord channels hosting malicious APKs, a delivery method noted as helping it evade detection. The surrounding reporting on Android banking trojans indicates this malware category commonly targets banking credentials and financial access, often using techniques such as overlay attacks, SMS interception, abuse of accessibility services, keylogging, screen recording, and remote control, but the provided content does not attribute those specific capabilities directly to DoubleTrouble itself. High-confidence associations in the provided content are that DoubleTrouble is an Android/mobile banking trojan, it targets European banks, and its observed infection vectors include phishing sites and Discord-hosted malicious APKs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android banking trojan spread via phishing sites and later via malicious APKs hosted on Discord channels to evade detection.
Mobile banking trojan referenced as being revealed in reporting; likely focused on credential/financial theft on mobile devices.
DoubleTrouble is an Android banking trojan targeting European banks, designed to steal credentials and financial information from infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.