Vultur is an Android banking trojan focused on on-device fraud, credential capture, and remote takeover of infected smartphones. First identified in 2021, it became notable for replacing traditional overlay-heavy banking malware tradecraft with screen streaming and remote-control capabilities that let operators observe and manipulate banking sessions directly on the victim device. This approach reduces reliance on static phishing overlays and supports real-time fraud against banking and cryptocurrency applications.
Vultur is closely associated with the Brunhilda dropper ecosystem, which has been used to distribute it through trojanized Android applications, including apps published on Google Play and apps masquerading as security or utility software. Observed delivery has included staged dropper behavior in which a seemingly functional application prompts the victim to install an update or additional package, after which the Vultur payload is deployed. More recent campaigns also used hybrid social engineering involving SMS messages and phone calls to convince victims to install a trojanized security-themed application.
Core Vultur functionality includes screen recording or screen streaming, Accessibility Services abuse, keylogging or accessibility-based input capture, and VNC-like remote access. Operators can monitor foreground applications, capture user interactions, and remotely perform actions on the device to facilitate account takeover and fraudulent transactions. Newer variants expanded remote interaction with commands for UI actions such as clicks, scrolling, swipes, muting audio, displaying attacker-controlled notifications, blocking selected applications, bypassing lock-screen protections, and managing files on the device. The malware has also used Firebase Cloud Messaging for command delivery and AES-encrypted communications to improve operational flexibility and stealth.
Vultur targets banking and cryptocurrency users and has been observed focusing on financial institutions in countries including the United Kingdom, the Netherlands, Germany, France, Italy, Spain, and Australia, with some targeting of U.S. financial applications as well. It also targets cryptocurrency wallet and exchange applications. Some variants maintained separate targeting logic for screen-streaming and keylogging objectives, and accessibility logging was expanded in part to compensate for Android protections that can obscure sensitive app windows during screen capture.
The malware shows continued development and increasing sophistication, including dynamic loading, string obfuscation, native-code payload decryption, staged payload chains, and masquerading under legitimate-looking package identities. Reporting has linked Vultur and Brunhilda closely enough that they are often assessed as operated or developed by the same threat actors. Vultur is widely regarded as an example of Android banking malware evolving toward RAT-like functionality and actor-controlled proprietary tooling rather than simple commodity overlay theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
First discovered by ThreatFabric in July 2021, Vultur is an Android banking trojan which specializes in stealing PII from infected devices using its screen-streaming capabilities.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
With Vultur fraud can happen on the infected device of the victim. These attacks are scalable and automated ... circumventing detection based on phishing MO’s that require fraud to be performed from a new device
In order to deceive unsuspecting individuals into installing malware, the threat actors employ a hybrid attack using two SMS messages and a phone call. First, the victim receives an SMS message that instructs them to call a number if they did not authorise a transaction involving a large amount of money... A second SMS is sent during the phone call, where the victim is instructed into installing a trojanised version of the McAfee Security app from a link.
These attacks are scalable and automated since the actions to perform fraud can be scripted on the malware backend and sent in the form of sequenced commands.
Brunhilda and Vultur have started using native code for decryption of payloads, likely in order to make the samples harder to reverse engineer.
Sideloading bypasses the official app stores’ rigorous vetting processes... [It leaves] devices exposed to malware and unauthorized code.
The latest version of Brunhilda also implemented a new layer of obfuscation, which encrypts strings by using AES with a varying key
in these new version, the installation logic is not contained in the main DEX file, but in a additional dex file which is loaded dynamically.
the dropper initially sends a registration message to its C2 server. As a response, the server sends back an appToken, which is then used in the following requests to identify the device.
Otherwise, it will receive a configuration data with the URL containing the payload.
nstart_vnc() libavnc.so public static void startVnc ( FileDescriptor fileDescriptor , VncSessionConfig config ... C2Commands . log ( "VNC: START VNC SERVICE" )
Threat Actors are known for monitoring public reports and adjusting infrastructure that believe may be compromised... the developers behind the Vultur banking trojan appear to have updated the naming scheme of their domain infrastructure in response to a public threat intelligence report.
Below we can see that several of the domains have historically resolved to the same IP address of 82.221.136[.]47... there are malicious domains routing through it.
Threat Actors are known for monitoring public reports and adjusting infrastructure that believe may be compromised... the developers behind the Vultur banking trojan appear to have updated the naming scheme of their domain infrastructure in response to a public threat intelligence report.
114 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for mobile malware with permissions enabling remote interaction, screen capture, accessibility abuse, and interaction with finance apps.
A newly identified mobile malware family mentioned in the report as part of the rise in mobile Trojan activity.
Banking trojan whose developers updated domain infrastructure naming schemes; the content focuses on identifying additional malicious domains tied to its dropper distribution infrastructure.
A banking trojan whose operators updated domain naming schemes for malicious infrastructure, with observed dropper distribution URLs and newly identified domains tied to the same infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.