AmexTroll is an Android banking malware family active since the second half of 2021 and associated with financially motivated mobile fraud campaigns. It emerged as a distinct family separate from malware often collectively labeled as Brata. The malware has been linked to actors assessed as likely originating from Brazil, and it has been observed evolving from early campaigns against Italian institutions to broader operations targeting financial organizations in Great Britain and Australia.
AmexTroll is designed to facilitate credential and personal-information theft as well as operator-assisted on-device fraud. A defining characteristic is its use of overlays, including a distinctive black-screen overlay feature, to obstruct the victim interface and trigger phishing content rendered through embedded web components. This enables theft of banking-related information and other personally identifiable data. The family also supports screenshot-based screen streaming that gives operators near real-time visibility into the infected device, allowing remote guidance of fraudulent activity directly on the victim handset. In addition, it can remotely trigger a factory reset, a capability that can be used to disrupt recovery or hinder post-incident analysis.
Campaigns involving AmexTroll have used applications masquerading as security-related software and, in at least one observed operation, a dropper distributed through Google Play. The family reflects the broader shift in Android banking malware from simple credential harvesting toward interactive, on-device fraud against mobile banking users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
both generate a series of screenshots every few milliseconds, which then send to the C2 to mimic a real-time video stream. In this way, operators on the other side can interact with the device remotely, allowing criminals to perform actions directly on the infected device.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of Brazilian mobile malware families that gained prominence and expanded to Europe.
Android banking malware focused on on-device fraud. It uses overlays, WebView phishing pages, screenshot-based screen streaming, Accessibility abuse, and a distinctive black overlay feature to hide malicious activity. It expanded from Italian targets to institutions in Australia and Great Britain and was marketed under a rental/beta scheme.
Android banking malware focused on on-device fraud. It uses overlays, WebView phishing pages, screen streaming via repeated screenshots, Accessibility abuse, and a black-screen overlay to hide malicious activity. It expanded from Italian targets to institutions in the UK and Australia and was marketed under a rental scheme.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.