Xenomorph is an Android banking trojan first identified in 2022 and associated with the Hadoken Security Group. It targets mobile banking, payment, email, and cryptocurrency applications, initially focusing on European institutions and later expanding to hundreds of financial targets across multiple regions. The malware is designed to steal credentials and other sensitive financial data through overlay attacks, interception of SMS messages and notifications, and abuse of Android Accessibility Services. Later variants significantly expanded its functionality with runtime modules that enabled remote-access-style interaction, automated gestures and touches, SOCKS proxy support, cookie theft, and a full Automated Transfer System capable of carrying out end-to-end fraud on the victim device, including credential capture, MFA interception, balance checks, transaction initiation, and transfer completion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These new campaigns feature a new and improved version of Xenomorph, which added RAT capabilities thanks to the addition of a handful of... 'Runtime modules'.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
It was distributed through a fake one-page website containing only two buttons... the “Download for Android” button leads to downloading samples of Ermac... modified legitimate application was downloaded from malicious website mimicking the original website of the application. Victim is navigated there through malicious advertisement.
The malware will periodically poll for new commands from the C2, receiving the following response: { "type" : "get_coms" , "coms" : [ "<COMMANDS>" ] }
Xenomorph, just like the other malware families previously mentioned, starts a browser with JavaScript interface enabled.
DexClassLoader is used in a single place... This method loads dynamically the decrypted payload stored on the filesystem in “filename”
Here the banking payload has the Telegram page link encoded with RC4 encryption... ThreatLabz also observed RC4 encoded C2 domains stored inside the code.
after installation, the bot will always request overlays from the C2, which will send back an encrypted JSON configuration, with the URLs where the overlays are hosted.
Ermac.C, having the following capabilities... Keylogging... It is worth noting that authors of Xenomorph... enhanced with keylogging functionality
Xenomorph creates an overlay onto legit banking applications to trick users into entering their credentials.
It is also capable of intercepting users’ SMS messages and notifications, enabling it to steal one-time passwords and multifactor authentication requests.
after installation, the bot will always request overlays from the C2, which will send back an encrypted JSON configuration, with the URLs where the overlays are hosted.
This banking malware later reaches out to the command-and-control (C2) servers decoded either via Telegram page content or from a static code routine to request further commands, extending the infection.
Upon successful login, the browser will extract the cookie using the Android CookieManager and will send it to the C2 server
Latest versions of it are enhanced with keylogging functionality, accessibility actions engine as well as SOCKS proxy feature.
When the app is first opened, it reaches out to a Firebase server to get the stage/banking malware payload URL. It then downloads the malicious Xenomorph banking trojan samples from Github.
The screenshots in Figures 6 and 7 below show the C2 retrieval from a Telegram page. Here the banking payload has the Telegram page link encoded with RC4 encryption. Upon execution, the banking payload will reach out to the Telegram page and download the content hosted on that page.
143 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a mobile banking Trojan.
Android banking trojan embedded in Google Play apps that steals banking credentials, intercepts SMS messages and notifications to capture OTP/MFA prompts, abuses accessibility/device admin privileges for persistence, downloads payloads from GitHub, retrieves C2 information via Telegram or static encrypted routines, and uses overlays on legitimate banking apps to phish credentials.
Android banking malware using an Automated Transfer System (ATS) to bypass MFA and automate fraudulent transactions; steals credentials and data from banking apps and crypto wallets; newer versions steal session cookies; distributed via trojanized apps and a service called 'Zombinder'.
Android banking trojan focused on mobile fraud. The latest variant adds an Accessibility Services-powered runtime engine and a full ATS framework to automate the fraud chain, including credential/PII theft via overlays and keylogging, transaction automation, MFA code theft, cookie stealing, SMS interception, app control, and funds exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.