SharkBot, an Android banking trojan targeting European banks, was found masquerading as legitimate mobile apps and abusing Accessibility Services to seize broad device control, steal credentials, intercept or send SMS messages, and launch overlay attacks against banking users. Researchers said the malware hid its icon after installation, maintained command-and-control connectivity by evading battery restrictions, and used encrypted communications, geofencing, sandbox evasion, and an uncommon Android DGA capability. Early analysis indicated the malware was likely still being actively developed, with incomplete features, test strings, and signs it may have been built as a private botnet.
The malware was later distributed through multiple malicious Google Play droppers, including fake antivirus, cleaner, tax-code, and file-manager apps, with researchers linking SharkBot delivery to at least six Play Store apps and estimating tens of thousands of installs across campaigns. One fake Italian tax app alone drew more than 10,000 installs, while broader Android dropper activity tied to SharkBot and other banking malware exceeded 130,000 cumulative installations. The campaigns primarily targeted users in Italy and the UK, with additional exposure in the Netherlands, Germany, and France, and Google removed identified apps after researcher notification, though SharkBot activity continued to evolve after the takedowns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
ThreatFabric discovered three new Brunhilda-linked Google Play droppers, with installation counts ranging from 1,000 to 100,000, that posed as authenticator or file-recovery apps and delivered a new Vultur variant.
ThreatFabric identified a second SharkBot dropper on Google Play disguised as a file manager, configured for Italy and the UK, and noted it was quickly removed after discovery.
In early October 2022, ThreatFabric observed a SharkBot campaign targeting Italian banking users through a fake Google Play app named "Codice Fiscale 2022," with SharkBot versions 2.29 through 2.32.
Fox-IT reported a new SharkBot Google Play campaign distributing fake antivirus and cleaner apps that dropped SharkBot v2 payloads, replacing the earlier Accessibility-based auto-install flow with a fake app-update prompt to evade review. The campaign initially targeted the UK and Italy, and Fox-IT later observed infrastructure expanding targeting to Spain, Australia, Poland, Germany, the United States, and Austria.
The additional SharkBot dropper applications discovered later in March were removed from Google Play.
The initially reported SharkBot dropper applications were removed from Google Play after Check Point reported them to Google.
Check Point reported that SharkBot activity peaked in early March 2022, with observed targeting concentrated mainly in Italy and the United Kingdom.
Check Point Research found additional SharkBot dropper applications on Google Play on March 15 and March 22, expanding the known set of malicious apps distributing the malware.
Check Point Research discovered four SharkBot dropper applications on Google Play that masqueraded as antivirus or cleaner apps and were tied to malicious developer accounts.
Cleafy Threat Intelligence discovered the SharkBot Android banking trojan at the end of October 2021 and assessed from early samples that it was likely still under development and operating as a private botnet.
ThreatFabric had previously discovered the Vultur Android banking trojan, which it linked to the Brunhilda Project crew and described as using screen-streaming and VNC-based remote session capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
threatfabric.com
Open sourceblog.fox-it.com
Open sourceresearch.checkpoint.com
Open sourcecleafy.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.