SharkBot is an Android banking malware family first reported by the Cleafy Threat Intelligence Team at the end of October 2021. It steals banking credentials and banking details and is described as one of the notable mobile banking malware families active in 2022. The malware targets Android devices and performs overlay attacks against targeted applications, especially banking and cryptocurrency apps. It abuses Android Accessibility Services to control the device, interact with app interfaces, auto-fill fields, simulate clicks and gestures, and support Automatic Transfer System (ATS) fraud to initiate unauthorized money transfers.
Documented capabilities include intercepting, hiding, collecting, and exfiltrating SMS messages; stealing contacts; keylogging victim keystrokes; stealing cookies; and exfiltrating captured user credentials and event logs to command-and-control infrastructure. SharkBot can hide and send SMS messages, change the device’s default SMS handler, and on some Android versions request or abuse SMS-related permissions, including becoming the default SMS app. Older samples implemented an Auto Direct Reply feature that replied to intercepted message notifications with malicious links used to spread a SharkBot dropper or APK, while newer versions reportedly removed that feature.
For command and control, SharkBot uses HTTP, including HTTP POST requests to send device status and permission information, and can receive commands such as stopAll, openPackage, removeApp, getDoze, ats, enableKeyLogger, and sendSMS. In addition to hard-coded infrastructure, SharkBot uses a fallback domain generation algorithm (DGA), which is noted as unusual for Android malware. Multiple DGA versions are described: 0.0.0, 1.63.3, 2.1, and 2.8. Earlier variants used Base64-derived domains based on the current week and a hardcoded string; later variants switched to MD5-derived generation using the current week, current year, and TLDs including .xyz, .live, .com, .store, .info, .top, and .net. Version 2.8 corrected a flaw present in 2.1 so generated domains differ across years.
Persistence and evasion behaviors include requesting Accessibility permissions, hiding the app icon, disrupting uninstall attempts by returning the user to the home screen, and anti-emulator checks that prevent launch or C2 communication when an emulator is detected.
High-confidence indicators mentioned in the content include package names com.btfezxwhygk2dw0gaj.eguafyojiqcw7a and com.ohalqpdj.discopet; hard-coded C2 URL http://f3eac8de096e59ca.live/; sample hashes 0356f17f28778da7c97dc8b661c0aeb0 / 2c4828f926471ec4f3522fc28dd4d8fdec692c35 / 76b4ee2da4e39677038ea033f25652fb02ed9e84ab829ce212fa1dfbc941df2c for version 0.0.0, 48ad4e0478e4d742f51848604d06130e / a9ca49ef2201707b7bcf57798fc67e69d238c900 / c14f413d8ed944ba7e4364e6b17585019fd622feeb4b53f7002a742d7389e08a for version 1.63.3, 92011ba743860567b85f46aedf360661 / 506df2fd2e638ab614eeb4cbc416bd46fdbf6a19 / 70b244a03a0eacd00cc52ea8863af2c459eb8dc2e6bf5887e657b401e0477485 for version 2.1, 2dfe83d4d7c0b5e0cfc0537efdbbbb01 / f1a820369f02a696e8bcaecee464eeaef0847c44 / dae193b7cac6d048dcc37916c92b0d2b11c56aa3f45e9995c16417e3b0587404 for version 2.8, and SHA256 hashes d05fb8c6899c96d1519e46eaea848ead6a17c7ddd0e20228e83c1aa9f264011d for an older sample and bf3fcdba7148627abfed402d038c99d3b2e60cd87cd04fe22b6ea3aac5ac9151 for a SharkBot v2.6 sample.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware will perform overlay attack when the victim opens a specific app usually banking apps or cryptocurrency apps to steal the victim’s credentials.
SharkBot is an Android banking malware that steals credentials and banking details. Apart from one or two hard-coded domains, it relies on a fallback domain generation algorithm (DGA) for communication.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another active mobile banking malware family in 2022.
Android banking trojan that steals SMS, contacts, cookies, and credentials via overlay attacks and keylogging; abuses accessibility services for ATS (Automatic Transfer System) fraud to automate money transfers; intercepts SMS for OTP theft; uses DGA for C2 resilience; includes anti-emulator and persistence features.
Android banking malware that steals credentials and banking details and uses a fallback domain generation algorithm (DGA) for command-and-control communication. The content discusses multiple SharkBot versions and how its DGA evolved over time.
Android malware that can hide and send SMS messages and change the device's default SMS handler.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.