Gustuff is an Android banking trojan focused on large-scale theft from banking, payment, fintech, marketplace, messaging, and cryptocurrency applications. It emerged in 2018 and has been described as an evolution of AndyBot. The malware is associated with Russian-speaking cybercriminal activity but has primarily targeted victims outside Russia, including users in Australia, the United States, Poland, Germany, India, and other international markets.
Gustuff is notable for extensive abuse of Android Accessibility Services to automate fraud directly on the victim device. It can monitor user interaction, intercept input, determine when targeted applications are active, and manipulate interface elements inside legitimate apps. This enables overlay-based credential theft, collection of device unlock codes, and Automated Transfer System functionality that can autofill fields, navigate banking workflows, inspect balances, and initiate fraudulent transactions from the victim’s own device. It has also used fake push notifications and WebView overlays to impersonate banks and cryptocurrency services and solicit credentials.
The malware supports interception of SMS messages, including two-factor authentication codes, and can collect contacts, device identifiers, files, and photos from compromised devices. Reported variants also check for installed antivirus or security software, dynamically retrieve target application lists and blocking lists from command-and-control infrastructure, and communicate over standard HTTP-based channels. Some versions included additional capabilities such as sending SMS messages for propagation, issuing USSD requests, launching proxy functionality, executing scripts through embedded web components, and interactive accessibility-driven remote actions.
Gustuff has been distributed primarily through SMS phishing campaigns carrying links to malicious Android application packages, with infected devices sometimes used to send further lure messages to harvested contacts. Campaigns have heavily targeted financial institutions and cryptocurrency wallets, and later expanded to government and employment-related applications. The family is widely recognized as an early and influential example of highly automated Android banking malware that shifted from simple credential theft toward on-device fraud execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Gustuff is also able to display fake push notifications with legitimate icons... either a web fake downloaded from the server pops up and the user enters the requested personal or payment (card/wallet) details
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
The malware is also capable of sending information about the infected device to the C&C server
Gustuff pings the C2 at a predetermined interval, which will either reply with an 'ok' or it will issue the command to be executed.
It can receive a command to create a webview targeting specific domains, while fetching the necessary injections from a remote server.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another banking trojan that abuses Android accessibility services for malicious activity.
Mentioned as an example of advanced Android banking malware with similar functionality.
Mentioned as the first banking malware cited here to implement ATS in 2018.
Android banking trojan that spreads via SMS links to malicious APKs, abuses Android Accessibility Service to automate fraudulent transactions via ATS, displays fake push notifications and web fakes, steals banking and cryptocurrency account data, sends/reads SMS, sends USSD requests, launches a SOCKS5 proxy, transfers files to C2, and can reset infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.