MazarBOT is an Android banking Trojan associated with mobile financial fraud. It is known for intercepting SMS-based two-factor authentication codes, including codes delivered by online banking applications, enabling attackers to bypass transaction verification and account-protection workflows. The malware is part of the wave of sophisticated Android banking threats that also includes families such as BankBot, Anubis, and Exobot.
MazarBOT has been delivered through unsolicited SMS messages containing links to download the malicious application, indicating smishing-based initial access and sideloaded installation outside trusted app stores. As an Android banking Trojan, it fits the broader pattern of mobile malware that masquerades as legitimate applications and abuses intrusive permissions to gain access to sensitive device functions.
Its primary operational value lies in facilitating banking fraud by capturing authentication messages used in financial transactions. MazarBOT has been cited among notable Android threats from the mid-2010s banking botnet era and is representative of malware designed to undermine SMS-based security controls on mobile devices. The available high-confidence reporting directly supports Android targeting, SMS interception for two-factor bypass, and SMS-link delivery, but does not provide sufficient corroborated detail here to attribute additional specific behaviors beyond those facts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
It exploits an issue known as activity hijacking in older Android devices that allow an overlay to be displayed over a legitimate application. The overlay looks like what a user would expect to see after launching a legitimate banking app, but that app is actually running underneath the overlay. The user then inputs their authentication credentials, which are sent to the attackers.
Gustuff can intercept two-factor authentication codes transmitted via SMS. MazarBOT can intercept two-factor authentication codes sent by online banking apps.
It exploits an issue known as activity hijacking in older Android devices that allow an overlay to be displayed over a legitimate application. The overlay looks like what a user would expect to see after launching a legitimate banking app, but that app is actually running underneath the overlay. The user then inputs their authentication credentials, which are sent to the attackers.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking malware/bot that intercepts SMS-based authentication codes used by online banking apps.
Android malware delivered through unsolicited SMS messages linking to a download URI.
Android malware that intercepts two-factor authentication codes sent via SMS by online banking apps.
Android banking trojan that intercepts SMS-based two-factor authentication codes used by online banking apps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.