HookBot is an Android malware family associated with mobile banking fraud and remote device control. Publicly exposed builder-panel and APK source artifacts indicate a modular Android bot architecture with components for accessibility-service abuse, screen capture, device-administration functions, notification handling, SMS-related actions, command processing, socket-based communications, and web-injection style functionality. These features are consistent with Android banking trojan behavior focused on intercepting user activity, manipulating the device interface, and enabling operator-directed post-compromise actions.
HookBot appears to support centralized command-and-control through a dedicated builder or management panel, suggesting operator customization of payloads and campaign configuration. The presence of accessibility and screen-projection components indicates capability for surveillance and interaction with victim devices beyond simple data theft, while notification and SMS-related modules are consistent with interception of messages and abuse of mobile authentication workflows. Device-admin and lock-device components indicate persistence and resistance to removal on infected Android devices.
HookBot has also been observed in malicious hosting ecosystems alongside other commodity malware and command-and-control infrastructure, including environments linked to bulletproof hosting providers. This places it within broader cybercriminal service infrastructure rather than tying it with high confidence to a single state actor or intrusion set. The available evidence supports classifying HookBot as Android malware used for financially motivated operations, particularly those involving banking-style overlays, remote control, and theft of sensitive information from mobile devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
777 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware family listed as detectable via favicon hash hunting of exposed infrastructure.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Malware family observed as command-and-control infrastructure hosted on the abusive networks discussed in the report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.