Researchers documented multiple evolutions of the BianLian Android banking trojan, showing a malware family that abuses Accessibility Services to seize control of infected devices, hide its launcher icon, deploy overlay attacks, intercept SMS, execute USSD commands, lock screens, and target banking and cryptocurrency users. Fortinet reported a heavily obfuscated variant that dynamically loads a secondary APK downloaded from command-and-control infrastructure rather than decrypting it from app assets, and noted that the payload checks whether Google Play Protect is enabled through the SafetyNet API.
Later analysis of a newer sample found BianLian continuing to broaden both its infrastructure and victim scope, using a Tor onion service to deliver a Base64-encoded JSON configuration containing multiple C2 domains and targeting 438 mobile applications, primarily banking apps. The malware also added or refined remote-access capabilities including screen recording via MediaProjection and a SOCKS5/SSH proxy with remote port forwarding, while reorganizing code to improve persistence and evasion on major Android vendors by handling battery optimizations, disabling Huawei and Samsung protections, and enabling autostart on Xiaomi MIUI devices.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
An analysis of an Android/BianLian sample documented a malformed APK ZIP structure with an incorrect CRC32 for AndroidManifest.xml and a packer that decrypted a hidden payload from assets and loaded it via reflection at runtime. The unpacked payload exposed typical BianLian modules including SMS, USSD, screen locker, injections, SOCKS5, screencast, and sound switching.
A June 2022 analysis documented a new BianLian sample, doc_hy_0906_obf.apk, that retrieved command-and-control domains from a Tor onion site returning a Base64-encoded JSON object. The sample targeted 438 applications and reorganized code for battery optimization handling, device security bypasses, and Xiaomi autostart enablement without adding major new functionality.
An analyst noted that BianLian’s targeting of some French banks was a recent addition first seen in May 2022. This represented an expansion in the malware family’s targeting profile.
A BianLian Android sample masquerading as a video player was served from a malicious URL at the beginning of January 2022. The sample was later assessed as a BianLian bot and notable for unpacking its payload via re-implemented Android multidex support rather than DexClassLoader.
FortiGuard Labs analyzed a heavily obfuscated Android sample and identified it as a new BianLian variant targeting mainly Turkish banking and financial apps. The sample added screen-recording via MediaProjection and an SSH-based SOCKS5 proxy module using JSCH, while downloading its payload APK from C2 infrastructure.
ThreatFabric published research describing BianLian as a malware family that originally acted as a dropper before developing its own banking functionality. This marked an early documented evolution of the family’s capabilities.
ThreatFabric first publicly discussed the BianLian Android malware family in 2018. Fortinet later referenced this as the earliest cited public reporting on the family.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
cryptax.medium.com
Open sourcecryptax.medium.com
Open sourcecryptax.medium.com
Open sourcecryptax.medium.com
Open sourcefortinet.com
Open sourcethreatfabric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.