Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
With that, it tries to protect this component and itself from being uninstalled... If any of these events are detected, the trojan returns the victim to the home screen... And if the trojan detects an attempt to delete it or the main component, the trojan simulates the user pressing the back button. If the primary malicious component is ultimately deleted, the trojan will reinstall it.
An application package of the Android.BankBot.Coper.2 contains a dex file that is located in \res\raw\syxinxxjzdmhf and encrypted with the RC4 algorithm. This file is an Android.BankBot.Coper.1.origin banking trojan. A native library liblfxeKfnTv.so and a ngLlO6J4EqyiYVjCBS3psvf8kwkw6JNt key is used to decrypt it.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan delivered by the Android.BankBot.Coper.1 dropper. It masquerades as a system app ('Cache plugin'), contains an encrypted dex payload, decrypts and launches a banking trojan module, and hides its icon from the installed apps list.
Referenced as the installed APK containing the main malicious component that performs the primary malicious actions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.