Rotexy is an Android banking Trojan that combines financial-fraud functionality with ransomware-style screen-locking behavior. It has been observed as a notable mobile banking malware family and was reported among the more prevalent Android banking threats in 2019 and 2020.
Rotexy targets Android devices and focuses heavily on SMS-based fraud workflows associated with banks, payment systems, and mobile network operators. It can monitor incoming SMS messages, filter them using sender information, keywords, and regular expressions, automatically reply to messages, optionally delete them, and transmit SMS content or full message lists to command-and-control infrastructure. These behaviors support interception of banking notifications and one-time codes, as well as concealment of attacker activity from the victim.
The malware also performs device profiling and data theft. Reported collection includes the device IMEI, phone number, network operator, operating system version, device model, registration country, and the victim’s contact list, which can be uploaded to its operators. For command and control, Rotexy has used JSON-formatted messages over HTTP POST and has also leveraged Google Cloud Messaging, indicating a flexible mobile-centric C2 design.
Overall, Rotexy is best characterized as an Android banking Trojan with SMS interception, device reconnaissance, and data exfiltration capabilities, augmented by blocker-style behavior associated with mobile ransomware tactics.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
DEFENSOR ID has used Firebase Cloud Messaging for C2; Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging; Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions.
Gustuff gathers the device IMEI to send to the command and control server; Rotexy collects the device's IMEI and sends it to the command and control server; RuMMS gathers the device phone number and IMEI and transmits them to a command and control server.
DEFENSOR ID has used Firebase Cloud Messaging for C2. Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging. Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions. SpyC23 can communicate with the Command and Control server using HTTPS and Firebase Cloud Messaging (FCM). Trojan-SMS.AndroidOS.Agent.ao uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.FakeInst.a uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.OpFake.a uses Google Cloud Messaging (GCM) for command and control.
Examples in the content include: 'Riltok can access and upload the device's contact list to the command and control server,' 'Rotexy can access and upload the contacts list to the command and control server,' and multiple entries stating malware can 'exfiltrate' contacts.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware described as a banker and ransomware that uses phishing overlays to steal credit card information.
Android banking trojan that filters, processes, and exfiltrates SMS messages, with emphasis on banks, payment systems, and mobile operators.
Mobile banker with ransomware functionality that communicates with C2 via HTTP POST JSON payloads and Google Cloud Messaging.
Mobile malware described as banker and ransomware that collects installed app lists and exfiltrates them to C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.