Researchers reported that Ghimob, an Android banking trojan linked to Brazil’s Guildma operation and the broader Tétrade malware family, was built to steal from users of financial and cryptocurrency apps by letting operators control transactions directly on infected phones. The malware is delivered through malicious links that serve either Windows ZIP archives or Android APKs based on the visitor’s user agent, tying the mobile activity to infrastructure also used in Guildma’s Windows campaigns. Although early observed victims were in Brazil, the malware was configured to target institutions in multiple countries, including Paraguay, Peru, Portugal, Germany, Angola, and Mozambique.
Ghimob abuses Android Accessibility services to gain persistence and remote-control capabilities, then hides its icon and interferes with uninstallation and shutdown attempts to stay on the device. Its command-and-control design also reflects the fallback channel pattern tracked as MITRE ATT&CK T1008, using redundant methods to recover real C2 servers through Cloudflare-protected infrastructure and DGA-like techniques when primary paths are unavailable. The combination of anti-analysis checks, resilient C2, and on-device fraud execution makes Ghimob a capable mobile banking threat with clear potential for international expansion.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
At the time of observation, telemetry indicated that observed Ghimob victims were located in Brazil. The malware was also configured to target financial and cryptocurrency apps across multiple other countries, suggesting potential international expansion.
The campaign used creditor-themed emails containing malicious links that delivered either a Windows ZIP archive or an Android APK depending on the visitor's user-agent. The APKs were hosted on malicious domains registered by Guildma operators and masqueraded as apps such as Google Defender, Google Docs, and WhatsApp Updater.
Kaspersky researchers found the Ghimob Android banking trojan while monitoring a Windows malware campaign associated with the Brazilian Guildma threat actor. The discovery linked the mobile malware to Guildma and the broader Tétrade banking trojan ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.