BRATA is an Android banking trojan first observed in Brazil in 2019 and later associated with campaigns targeting banking customers in Europe, especially Italy. It is designed for on-device fraud against mobile banking users. Core behavior attributed to the original BRATA includes abuse of Android Accessibility Services to capture victim input and facilitate operator control, collection of account information from compromised devices, retrieval of Android system and hardware information, and exfiltration of stolen data to command-and-control infrastructure. BRATA has been observed communicating with its operators over HTTP and WebSockets.
Campaigns associated with BRATA have used mobile-focused social engineering chains in which victims receive bank-themed SMS lures leading to phishing or malware-delivery pages, followed in some cases by phone calls from fraud operators who persuade victims to install the malicious application and grant permissions. Once installed, BRATA variants have been reported to request permissions that support banking fraud, including accessibility abuse and SMS interception, and to include screen recording or casting functionality that enables attackers to observe or interact with the victim device during fraudulent transactions.
Later reporting has argued that some malware long grouped under the BRATA label actually comprises distinct Android banking malware families, notably AmexTroll and Copybara, rather than new BRATA variants. Under that interpretation, the original BRATA family is primarily tied to the earlier Brazil-focused activity and no new original BRATA samples were observed after 2019. Even with that taxonomy dispute, BRATA remains widely recognized as an Android banking trojan associated with credential and account-data theft, remote fraud enablement, and mobile-banking-focused social engineering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Malicious actors are resorting to voice phishing (vishing) tactics to dupe victims into installing Android malware on their devices... Telephone-oriented attack delivery (TOAD)... involves calling the victims using previously collected information from the fraudulent websites.
the first appearance of this name dates back to middle of 2019, while this malware family was reported to abuse a CVE in the popular instant messaging application WhatsApp to target victims in Brazil.
In some cases, the link redirects the victim to a phishing page that looks like the bank’s, and it is used to steal credentials and other relevant information (e.g. fiscal code and security questions).
In some cases, the link redirects the victim to a phishing page that looks like the bank’s, and it is used to steal credentials and other relevant information (e.g. fiscal code and security questions).
BRATA can use both HTTP and WebSockets to communicate with the C2 server. GPlayed has communicated with the C2 using HTTP requests or WebSockets as a backup. LightSpy has used both HTTPS and Websockets to communicate with the C2. | AbstractEmu can use HTTP to communicate with the C2 server; AhRat can communicate with the C2 using HTTPS requests; Android/AdDisplay.Ashas has communicated with the C2 server using HTTP; Android/Chuli.A used HTTP uploads to a URL as a command and control mechanism; Asacub has communicated with the C2 using HTTP POST requests; BOULDSPY uses unencrypted HTTP traffic between the victim and C2 infrastructure; BRATA can use both HTTP and WebSockets to communicate with the C2 server; Bread communicates with the C2 server using HTTP requests; PROMETHIUM used StrongPity to communicate with the C2 server using HTTPS; Cerberus communicates with the C2 server using HTTP; Chameleon can use HTTP to communicate with the C2 server; CHEMISTGAMES has used HTTPS for C2 communication; Concipit1248 communicates with the C2 server using HTTP requests; Corona Updates communicates with the C2 server using HTTP requests; Dark Caracal controls implants using standard HTTP communication; EventBot communicates with the C2 using HTTP requests; Exobot has used HTTPS for C2 communication; Exodus One checks in with the command and control server using HTTP POST requests; FluBot can use HTTP POST requests on port 80 for communicating with its C2 server; FlyTrap can use HTTP to communicate with the C2 server; Golden Cup has communicated with the C2 using MQTT and HTTP; GoldenEagle has used HTTP POST requests for C2; GPlayed has communicated with the C2 using HTTP requests or WebSockets as a backup; Gustuff communicates with the command and control server using HTTP requests; Hornbill can use HTTP and HTTP POST to communicate information to the C2; INSOMNIA communicates with the C2 server using HTTPS requests; LightSpy has used both HTTPS and Websockets to communicate with the C2; Red Alert 2.0 has communicated with the C2 using HTTP; RedDrop uses HTTP requests for C2 communication; Riltok communicates with the command and control server using HTTP requests; Rotexy can communicate with the command and control server using JSON payloads sent in HTTP POST request bodies; RuMMS uses HTTP for command and control; SharkBot can use HTTP to send C2 messages to infected devices; SilkBean has used HTTPS for C2 communication; Skygofree can be controlled via HTTP; SpyC23 can communicate with the Command and Control server using HTTPS; TrickMo communicates with the C2 by sending JSON objects over unencrypted HTTP requests; ViceLeaker uses HTTP requests for C2 communication; YiSpecter has connected to the C2 server via HTTP.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of Brazilian mobile malware families that gained prominence and expanded to Europe.
Referenced as a well-known Android banking trojan that heavily relies on Accessibility Service.
Android banking malware family referenced as being confused with Copybara and used in smishing-plus-vishing social engineering campaigns.
Android banking malware family first seen in 2019 targeting victims in Brazil, reportedly abusing a WhatsApp CVE and using Accessibility Service abuse for keylogging. The article argues later 'Brata' reporting conflated this original family with two distinct families, AmexTroll and Copybara.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.