Security researchers reported that the Android malware family Xbot evolved from a stealthy SMS-focused trojan into a broader banking and ransomware threat distributed through third-party app markets rather than Google Play. The malware masqueraded as trusted apps including Google Play, Opera Browser, Android Market, and Minecraft, then hid its launcher icon after installation to avoid detection. Early variants primarily targeted users in Russia and Eastern Europe, monitoring incoming SMS messages for selected keywords, exfiltrating messages to command-and-control infrastructure, sending premium-rate texts, downloading additional APKs, and persisting across reboots.
Later analysis found Xbot embedded in 22 malicious apps and expanded to phishing Google Play payment details and login credentials for multiple banking apps, including major Australian banks and at least one Russian bank. The trojan used activity hijacking and WebView overlays to present fake login and card-entry screens, stole SMS messages and contacts, abused device administrator privileges, and accepted remote commands from its operators. Researchers also found ransomware functions that could lock the device, set a password, encrypt files on external storage with a simple XOR routine, and demand a $100 PayPal My Cash Card payment, while added obfuscation and dormant call-recording code indicated active ongoing development.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks reported that the earliest Xbot sample they identified was compiled in May 2015, indicating the malware family had been under active development since at least that month.
Avast analyzed Xbot as an Android malware family targeting users in Russia and Eastern Europe, distributed through local Russian app markets while masquerading as apps such as Google Play, Opera Browser, Android Market, and Minecraft. Avast said it had observed 353 unique Xbot files and more than 2,570 unique install GUIDs since the beginning of February.
Palo Alto Networks disclosed a newer Xbot Android Trojan family found in 22 apps that phished Google Play payment cards and bank credentials, stole SMS and contacts, and could remotely lock devices and encrypt external-storage files for a $100 ransom. The researchers assessed it as a successor to Aulrin and noted targeting focused on Australia and Russia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
researchcenter.paloaltonetworks.com
Open sourceblog.avast.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.