SharkBot is an Android banking trojan and stealer first identified in late 2021. It is designed primarily for financial fraud and account takeover against mobile banking users, with campaigns notably targeting users in Italy and the United Kingdom before expanding to additional countries. The malware has commonly been distributed through malicious Android applications masquerading as antivirus, cleaner, tax, or file-management tools, including apps uploaded to Google Play, and later installs or updates the full payload on victim devices.
A defining characteristic of SharkBot is its aggressive abuse of Android Accessibility Services. After installation it persistently seeks accessibility privileges, uses them to automate permission grants, monitor foreground applications and user-interface events, capture text input, and interact with banking apps on the victim’s behalf. SharkBot supports overlay-based credential theft, keylogging via accessibility event capture, interception and concealment of SMS messages, SMS sending, contact theft, and exfiltration of captured credentials and event logs to command-and-control infrastructure over HTTP. It can also hide its launcher icon, request exemption from battery optimizations to maintain connectivity, interfere with uninstall attempts, and in some variants change the device’s default SMS handler.
Later SharkBot versions expanded beyond basic overlay fraud. Version 2.x introduced a refactored communication scheme and an evolving fallback domain generation algorithm for resilient command-and-control, an uncommon feature in Android malware. SharkBot also supports downloading additional modules and executing remote commands to open applications, uninstall selected apps, block access to targeted apps, and emulate user gestures. More advanced variants added Automatic Transfer System functionality to automate fraudulent transactions inside legitimate banking applications, and version 2.25 introduced session-cookie theft by loading attacker-controlled web content in a WebView and extracting banking session cookies after victim login.
SharkBot has shown anti-analysis and anti-emulation behavior, geofencing in some campaigns, and steady iterative development across multiple versions. Early reporting assessed it as a privately operated malware family rather than a broadly marketed commodity tool. Its combination of accessibility abuse, SMS interception, credential theft, ATS-driven fraud, and resilient command-and-control makes it one of the more capable Android banking trojans observed in the 2021-2022 period.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
the very first samples tracked down at the end of October use: a demo version of the Allatori Java Obfuscation
SharkBot hides itself with common names and icons posing as a legitimate application to the victims
removeApp ... the server sends a huge list of applications which should be uninstalled from the user’s device.
Sharkbot lures victims to enter their credentials in windows that mimic benign credential input forms. When the user enters credentials in these windows, the compromised data is sent to a malicious server.
Keylogging: this feature allows Sharkbot to receive every accessibility event produced in the infected device, this way, it can log events such as button clicks, changes in TextFields
SharkBot is able to read/send text messages, perform overlay attacks
CherryBlos has exfiltrated credentials collected from pictures that have been analyzed using optical character recognition (OCR).
Once the victim logged in to his bank account, the malware will receive the PageFinished event and will get the cookies of the website loaded inside the malicious WebView, to finally send them to the C2. | Version 2.25... introduced a new and interesting feature: Cookie Stealing or Cookie logger
Sharkbot lures victims to enter their credentials in windows that mimic benign credential input forms. When the user enters credentials in these windows, the compromised data is sent to a malicious server.
with the REQUEST_IGNORE_BATTERY_OPTIMIZATIONS permission, it is able to bypass Android's doze component and stay connected to the C2 servers to continue its malicious behavior
The exchange with the CnC server happens over HTTP with POST request on path / .
it uses an external module, downloaded from the C2, containing the ATS core functionalities and anti-detections technique used to slow down the static and dynamic analysis
Remote control/ATS: this feature allows Sharkbot to simulate accessibility events such as button clicks, physical button presses, TextField changes, etc.
206 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as another banking Trojan.
Mentioned as an example of advanced Android banking malware; also cited as having cookie stealer capabilities later mirrored by Xenomorph.
Referenced as another active mobile banking malware family in 2022.
Mentioned as another banking malware associated with ATS capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.