Zombinder is an Android malware delivery service and app-binding tool used to embed malicious payloads into otherwise functional legitimate-looking Android applications. It is designed to glue a secondary malicious component to a benign app so the trojanized application remains usable while covertly prompting the victim to install an additional payload, often disguised as an update or plugin. Zombinder has been advertised in cybercrime forums as a service capable of bypassing Android 13 and later Restricted Settings protections, enabling sideloaded payloads to obtain sensitive permissions such as Accessibility-related access that are commonly abused by mobile banking malware and spyware.
Zombinder has been observed as an installation stage in campaigns delivering Android banking trojans and spyware, including Octo2, Ermac, Sova, Xenomorph, and Datzbro. In these operations, victims are lured into installing trojanized apps masquerading as legitimate software such as utility, streaming, browser, VPN, social, or finance-related applications. After launch, the bound app requests installation of a supposed update or plugin that is in fact the malware payload. This approach supports defense evasion by preserving expected app functionality and reducing user suspicion while facilitating payload deployment on newer Android devices.
Operationally, Zombinder functions most specifically as a dropper or loader in the Android malware ecosystem. It has been linked to campaigns using fake websites, malicious advertisements, deceptive download pages, and other unofficial distribution channels rather than trusted app stores. Its role is not the final theft or fraud payload itself, but the covert installation and delivery of downstream malware that may then perform credential theft, keylogging, remote device control, session abuse, financial fraud, or broader post-exploitation activities. Zombinder illustrates the growing specialization of mobile cybercrime services, where third-party tooling is used to package, obfuscate, and distribute Android malware at scale.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
In the Octo2 campaigns that were spotted by ThreatFabric, we observed Zombinder serving as the first stage of the installation: upon launch, Zombinder will request the installation of an additional “plugin” which is, in fact, Octo2, thus successfully bypassing Android 13+ restrictions.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool used to bind or embed malicious code into otherwise functional Android applications so they appear legitimate while compromising the device in the background.
Android dropper used to deliver Datzbro and bypass security protections on newer Android devices.
First-stage installer/dropper used in observed Octo2 campaigns to sideload the Octo2 payload by presenting it as an additional plugin.
Android dropper/binder used as a distribution vector for Xenomorph v3 by binding malware to legitimate apps and delivering fake updates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.