Nexus is an Android banking trojan sold in cybercrime forums and widely assessed as a rebranded or closely related evolution of the S.O.V.A malware lineage. It targets Android devices, including versions up to Android 13, and is designed primarily for financial theft through credential harvesting, account takeover, and cryptocurrency wallet compromise. Nexus has been observed masquerading as legitimate Android applications and distributed through phishing infrastructure, including fake software download pages impersonating popular mobile apps.
On infected devices, Nexus abuses extensive Android permissions and Accessibility Services to automate permission grants, enable device-administration features, monitor user activity, and interact with other applications. Its functionality includes keylogging, SMS interception, contact and installed-application collection, notification suppression, call-related abuse, and exfiltration of device data to operator-controlled infrastructure. A core feature is its AppInject workflow: the malware reports installed applications to its command-and-control server, receives instructions when targeted banking apps are present, and downloads HTML overlay content that is displayed to phish credentials and other sensitive information from victims using banking applications.
Nexus has been reported targeting dozens of banking applications, with notable focus on institutions in Turkey and Spain, and it also targets cryptocurrency wallets by stealing wallet seed phrases and related data through Accessibility abuse. Some reporting attributes cookie theft and theft of one-time codes, including from authenticator applications, to the malware’s command set. In addition to banking-trojan behavior, Nexus has been described as incorporating a ransomware-style module capable of encrypting files on compromised Android devices.
The malware is associated with financially motivated cybercrime operations and has appeared in broader criminal ecosystems that combine mobile malware, phishing, credential theft, and cryptocurrency fraud. It has also been cited among prominent infostealer threats affecting Latin America and the Caribbean in 2025. Overall, Nexus is a multifunctional Android financial malware family centered on mobile banking fraud, credential theft, and wallet compromise, with strong emphasis on Accessibility-driven abuse and server-delivered phishing overlays.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Throughout 2025, Insikt Group observed threat actors targeting the LAC region by compromising remote desktop protocol (RDP), VPNs, and web admin panels, and obtaining credentials from prior infostealer infections, password reuse, brute-force attacks, and other initial access points.
Throughout 2025, Insikt Group observed threat actors targeting the LAC region by compromising remote desktop protocol (RDP), VPNs, and web admin panels, and obtaining credentials from prior infostealer infections, password reuse, brute-force attacks, and other initial access points.
Throughout 2025, Insikt Group observed threat actors targeting the LAC region by compromising remote desktop protocol (RDP), VPNs, and web admin panels, and obtaining credentials from prior infostealer infections, password reuse, brute-force attacks, and other initial access points.
Throughout 2025, Insikt Group observed threat actors targeting the LAC region by compromising remote desktop protocol (RDP), VPNs, and web admin panels, and obtaining credentials from prior infostealer infections, password reuse, brute-force attacks, and other initial access points.
151 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan used for mobile credential theft, stolen credential viewing, bot command dispatch, and cryptocurrency wallet seed phrase extraction via an exposed command-and-control panel.
A prominent infostealer threat observed in LAC in 2025.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Android banking trojan advertised on cybercrime forums and distributed via phishing pages masquerading as YouTube Vanced. It abuses Accessibility Services to grant permissions, keylog, steal SMS and contacts, perform HTML overlay/injection attacks against banking apps, extract 2FA codes, steal Trust Wallet and Exodus seed phrases and balances, and includes a ransomware module to encrypt files on infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.