SpyBanker is a banking malware family associated with theft of financial and other sensitive information from victim devices. The name has been used in multiple contexts, including Windows banking malware observed in Latin American cybercrime ecosystems and Android banking malware targeting mobile users. On Windows, SpyBanker has been identified among banking Trojans distributed through socially engineered campaigns that used malicious Control Panel application files as downloaders. In those operations, the initial downloader retrieved and launched a secondary banking payload that commonly implemented credential theft through techniques such as browser manipulation, keylogging, screen or mouse capture, and encrypted exfiltration. These campaigns heavily targeted Brazilian users and financial institutions and were commonly delivered through email lures themed around invoices, receipts, debt notices, and local payment documents. On Android, SpyBanker has been described as a banking trojan that abuses telephony features by hijacking call functions and redirecting calls through attacker-controlled numbers, enabling fraud against banking users. Across these usages, SpyBanker is best characterized as banking-focused credential theft malware aimed at financial fraud, with observed targeting centered on banking customers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking malware that manipulates call forwarding to redirect bank fraud-verification calls to attackers, aiding account takeover and fraud.
Android banking trojan spread via WhatsApp masquerading as a customer support tool; hijacks/redirects calls via attacker-controlled number (call interception/ATO enablement).
A banking trojan family referenced as a major malware family seen in CPL-related campaigns in Brazil. It steals victim information using multiple techniques and exfiltrates it to attackers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.