Asacub is an Android banking Trojan that became one of the most prevalent mobile financial malware families targeting users, particularly in Russia and later other regions. It is associated with mobile banking fraud and is known for masquerading as legitimate applications, including clients for popular classified-ad and free ads services, to deceive users into installation.
Asacub collects a broad set of victim data from compromised devices. Documented capabilities include harvesting SMS messages as they are received, sending SMS messages from the infected device, stealing the device contact list, and gathering device profiling information such as model, operating system version, and mobile network operator details. Its command-and-control communications have used HTTP POST requests, blending with ordinary application-layer traffic.
The malware’s SMS access supports both fraud and account takeover workflows common to Android banking malware, including abuse of mobile banking and interception of sensitive communications. Its contact and device-information collection also supports victim profiling and operational control. Asacub has been repeatedly identified in mobile threat reporting as a major Android banking malware family and remained a leading Android banking threat by victim share as late as 2020.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan listed in the expanding Android trojan market; appears in both Europe/USA and Russia lists.
Android banking trojan that disguises itself as a client for popular free advertising services.
Android banking trojan that collects incoming SMS messages.
Mobile banking trojan that communicates with command-and-control infrastructure over HTTP POST.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.