DroidBot is an Android banking trojan and remote-access malware family used to steal financial and other sensitive information from mobile devices. It has been identified in reporting on active mobile threat trends and is associated with abuse of Android accessibility features to monitor user activity and capture sensitive input. Documented behavior includes credential theft from banking workflows, screen monitoring, and keylogging-like collection of user-entered data, placing it among modern Android banker families that combine surveillance, overlay-based fraud, and remote control capabilities.
DroidBot targets Android devices and is relevant to campaigns focused on mobile banking users. Its tradecraft is consistent with financially motivated Android malware that relies on social engineering and malicious application installation outside trusted channels. The family has been referenced alongside other contemporary mobile banker threats as part of the broader rise in Trojan activity affecting smartphones. High-confidence public characterizations support classifying DroidBot as an Android banking trojan with credential theft and spyware-style monitoring functions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced for comparison as Android banking malware that abuses Accessibility for keylogging and screen monitoring.
Android RAT targeting banks and cryptocurrency exchanges, using overlay attacks, hidden VNC, keylogging, and UI monitoring.
A newly identified mobile malware family mentioned in the report as part of the rise in mobile Trojan activity.
Android banker offered as MaaS; abuses Accessibility for on-device fraud, credential theft, SMS interception, screenshots, and remote interaction; targets multiple EU countries with indicated plans for Latin America expansion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.