Researchers and Italy’s CERT-AGID reported that the Android banking trojan Oscorp, later tracked as UBEL, was distributed through a malicious APK site in Italy and evolved into a broader global campaign targeting more than 150 applications, including banking apps. The malware abused Android’s Accessibility Service to gain extensive control over infected devices, repeatedly coercing victims to grant accessibility, usage statistics, battery optimization exemptions, and sometimes device administrator privileges to maintain persistence and expand access.
Once active, UBEL/Oscorp could steal credentials through phishing overlays rendered in a WebView, intercept SMS messages, place calls, trigger call forwarding, execute USSD requests, launch or remove apps, and block legitimate applications. Analysts also documented screen and audio capture via WebRTC/STUN, HTTP POST communications with command-and-control servers, and specialized theft functions including replacement of cryptocurrency wallet addresses and harvesting of Google Authenticator one-time codes; published indicators included malware hashes, package names, C2 domains, injection paths, and AES keys tied to the operation.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Cleafy Labs reported that Oscorp had evolved into Oscorp/Ubel and documented its expanded capabilities and infrastructure. The analysis said the malware targeted more than 150 applications across multiple geographies and published associated hashes, package names, C2 domains, injection paths, and AES keys.
CERT-AGID published an analysis of the Android malware family it named Oscorp, describing its abuse of Accessibility Service, phishing overlays, SMS interception, call functions, device data theft, WebRTC-based audio/screen capture, cryptocurrency address replacement, and theft of Google Authenticator codes. The report also documented its package name, permissions, AES string encryption, C2 endpoints, and supported command set.
CERT-AGID reported that it had identified a website distributing a malicious Android APK in Italy. The reference indicates this as an early public notice tied to the malware activity later analyzed as Oscorp.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
developer.android.com
Open sourcecleafy.com
Open sourcecert-agid.gov.it
Open sourcecert-agid.gov.it
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.