Researchers reported that the Gustuff Android banking trojan evolved from an earlier malware family into a more capable fraud platform that spreads mainly through SMS links to malicious APKs and social-media-themed lures. Initially marketed on Russian-speaking criminal forums as an updated version of AndyBot, Gustuff was offered for lease and aimed largely at victims outside Russia. The malware was observed targeting users in Australia and other countries including the United States, Poland, Germany, and India, with victim lists spanning more than 100 banking apps, dozens of cryptocurrency services, fintech platforms, marketplaces, payment systems, messengers, hiring apps, and the Australian Government Portal.
The updated malware relies heavily on Android Accessibility Service to automate on-device fraud, including interacting with legitimate apps, displaying fake push notifications and overlays, and using an Automatic Transfer System to fill transaction fields. Researchers said newer versions reduced static indicators by loading target app lists dynamically from command-and-control servers and added JavaScript-based scripting, asynchronous task handling, improved command tracking, and an interactive mode for automated actions on infected devices. Gustuff also retained broad device-control features, including reading and sending SMS messages, issuing USSD requests, exfiltrating files and device data, launching a SOCKS5 proxy, disabling Google Protect in many cases, resetting devices, and maintaining resilience through an SMS-based secondary administrative channel when primary C2 infrastructure was disrupted.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Talos reported that a later campaign at the beginning of October used an updated version of Gustuff. The new version removed hardcoded target app lists, loaded targets dynamically from C2, and added JavaScript scripting and improved command handling.
Talos observed a Gustuff campaign around June 2019 that used Instagram-themed lures instead of earlier Facebook-themed lures to trick users into installing the malware. The campaign continued to rely primarily on malicious SMS messages for infection.
Group-IB said Gustuff was first discovered on hacker forums in April 2018, where the Russian-speaking developer 'Bestoffer' advertised it as an updated version of AndyBot. The malware was offered for lease at $800 per month.
According to Group-IB's report, the earlier AndyBot malware had been attacking Android phones since November 2017 using web fakes disguised as apps of international banks and payment systems. Gustuff was later described by its developer as an updated version of AndyBot.
During Talos's investigation, the malware received a command from its command-and-control server to target the Australian Government Portal, which hosts services such as taxes and social security. The related web injections were then loaded from C2 infrastructure.
After the initial Talos reporting, Gustuff operators changed their distribution hosts and later disabled their primary command-and-control infrastructure. Talos noted the operators still retained control of infected devices through a secondary SMS-based administrative channel.
Cisco Talos had previously reported on the Gustuff banking trojan in April before its later October 2019 update. That earlier reporting covered Gustuff as an Android banking trojan targeting financial institutions in Australia and noted its lineage from Marcher.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
group-ib.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.