Ghimob is an Android banking trojan associated with the Brazilian threat actor behind Guildma, one of the financially motivated malware operations commonly grouped within the Tétrade ecosystem. It targets mobile banking, fintech, payment, exchange, and cryptocurrency applications, with configurations covering institutions and services in Brazil, Paraguay, Peru, Portugal, Germany, Angola, and Mozambique. Observed victim telemetry was concentrated in Brazil, but the malware was built for broader international expansion.
The malware is designed to let operators conduct fraud directly on an infected victim’s smartphone, helping bypass anti-fraud controls that are more effective against remote access from attacker infrastructure. Ghimob abuses Android Accessibility services to obtain extensive control over the device, including monitoring active windows, capturing interface content, manipulating on-screen actions, and maintaining remote operator control. It can record a victim’s screen-lock pattern and later replay it to unlock the device. It also uses distraction techniques such as black-screen overlays or full-screen web content while fraudulent activity is performed in the background.
For persistence and defense evasion, Ghimob hides its icon after installation, interferes with manual removal, and can block restart or shutdown actions. It performs anti-analysis checks for emulation and debugging conditions and terminates when such checks are triggered. It also obscures its command-and-control resolution through fallback mechanisms and DGA-like techniques, using intermediary providers to retrieve the real server address.
Distribution has been linked to lure messages themed as creditor notifications that direct victims to malicious links. Delivery infrastructure has shown overlap with Guildma’s Windows campaigns, with the same distribution point serving different payloads depending on the visitor environment, including Android installers for mobile victims. Ghimob has masqueraded as legitimate application installers rather than relying on official app stores.
Overall, Ghimob is a mature mobile banking malware family focused on financial fraud, remote device manipulation, and operational resilience, representing the expansion of Brazilian banking-trojan tradecraft from Windows into Android.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently, their new creation, the Ghimob banking trojan, has been a move toward infecting mobile devices, targeting financial apps from banks, fintechs, exchanges and cryptocurrencies in Brazil, Paraguay, Peru, Portugal, Germany, Angola and Mozambique.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The APKs thus distributed are posing as installers of popular apps... the app itself pretends to be Google Defender, Google Docs, WhatsApp Updater, etc.
As soon as the malware is launched, it tries to detect common emulators, checks for the presence of a debugger attached to the process and the manifest file, and also checks for a debuggable flag. If any of these are present, then the malware simply terminates itself.
they can insert a black screen as an overlay or open some website in full screen, so while the user looks at that screen, the criminal performs the transaction in the background | Even if the user has a screen lock pattern in place, Ghimob is able to record it and later replay it to unlock the device.
Ghimob sends accessibility-related information from the current active window
This includes the phone model, whether it has a screen lock activated and a list of all installed apps that the malware has as a target including version numbers.
As soon as the malware is launched, it tries to detect common emulators, checks for the presence of a debugger attached to the process and the manifest file, and also checks for a debuggable flag. If any of these are present, then the malware simply terminates itself.
they can insert a black screen as an overlay or open some website in full screen, so while the user looks at that screen, the criminal performs the transaction in the background | Even if the user has a screen lock pattern in place, Ghimob is able to record it and later replay it to unlock the device.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan mentioned as part of possible platform expansion by Latin American banking trojan operators; explicitly attributed to the actor behind Guildma.
New banking malware created by the Guildma operators, targeting users across Latin America, Europe, and Africa.
A Brazilian-origin Android mobile banking trojan and RAT that abuses Accessibility services to gain persistence, prevent uninstallation, capture data from targeted financial apps, monitor screen content, record and replay screen lock patterns, hide its icon, and provide full remote control so operators can perform fraudulent transactions directly on the victim device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.