Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
2FA : Launch the Google 2FA app (then Oscorp is able to steal the codes abusing the Accessibility service)
Le stringhe ... decifra le stringhe ... Cipher.getInstance("AES/CBC/PKCS5Padding") ... Entrambi i parametri sono cifrati
This usually takes the form of an imitation app or a WebView launched “on-top” of a legitimate application
“The Overlay attack is a well-known technique implemented on modern Android banking trojans... This usually takes the form of an imitation app or a WebView launched ‘on-top’ of a legitimate application (such as a banking app).”
il servizio di accessibilità permette infatti di: Abilitare funzionalità di keylogger.
“The Overlay attack is a well-known technique implemented on modern Android banking trojans... This usually takes the form of an imitation app or a WebView launched ‘on-top’ of a legitimate application (such as a banking app).”
il servizio di accessibilità permette infatti di: Abilitare funzionalità di keylogger.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan that performs overlay attacks, steals 2FA codes via Accessibility abuse, sends and deletes SMS, forwards calls, launches apps and URLs, downloads phishing injection payloads from C2, blocks apps, records screen/audio via WebRTC/STUN, and can set itself as device admin.
Android malware that abuses Accessibility Service to steal credentials via phishing injections, capture keystrokes, send and intercept SMS, make calls, forward calls, disable security apps, collect device data, fetch commands from C2, block apps, steal cryptocurrency by replacing wallet addresses, capture audio/video via WebRTC, and steal Google Authenticator 2FA PINs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.