Researchers linked Octo and Coper to the Exobot malware lineage and described them as Android banking trojans built for large-scale on-device fraud. The malware abuses Android Accessibility Services and screen-capture features such as MediaProjection or VNC-style remote access to let operators view screens, steal credentials, intercept SMS and push notifications, log keystrokes, deploy overlay attacks, and remotely control infected devices while hiding activity with black-screen overlays, disabled notifications, and anti-removal tricks. Reports tied Octo’s rental operation to the actor known as "Architect" or "goodluck", while later infrastructure analysis connected active C2 servers to broad international campaigns with tens of thousands of bots and hundreds of thousands of intercepted SMS messages.
The trojans were distributed through malicious landing pages and rogue Android apps, including droppers published on Google Play that impersonated cleaners, screen recorders, Play Store installers, PDF viewers, and security tools. Observed campaigns used apps such as Fast Cleaner, Pocket Screencaster, UniFile manager – PDF viewer, and DawDropper-hosted utilities that fetched payloads from services like GitHub and Firebase. Initial Coper activity targeted Colombian banking users, but later campaigns expanded across Europe, the United States, Turkey, and other regions, with notable targeting of Spain, Portugal, Italy, Germany, Austria, Belgium, and Hungary.

Pull IOCs and campaign context straight into your stack.
17 events from the most recent confirmed update back to the earliest known activity.
Team Cymru analyzed Coper/Octo as a malware-as-a-service operation and linked active infrastructure through a recurring X.509 certificate pattern. The researchers said active campaigns heavily targeted Portugal, Spain, Turkey, and the United States, with nearly 45,000 bots and almost 700,000 intercepted SMS messages across known infrastructure at the time of analysis.
Team Cymru identified 91.240.118.224 as a Coper/Octo controller used in campaigns beginning on 5 February 2024. The attribution was based on VirusTotal uploads and the researchers' infrastructure analysis.
K7 Labs analyzed a Coper campaign in which a malicious Google Play app, 'UniFile manager – PDF viewer,' with more than 10,000 downloads fetched a second-stage APK from GitHub. The installed malware disguised itself as 'Play Market,' repeatedly requested Accessibility permissions, decrypted a payload named cermb, and used SMS interception and keylogging.
Trend Micro reported that DawDropper apps on Google Play distributed banking trojans including Octo, using Firebase Realtime Database to fetch payload locations and GitHub to host payloads. The report placed DawDropper within a broader 2022 trend of Android banking droppers.
Trend Micro's IOC list included a DawDropper sample, com.scando.qukscanner, that downloaded an Octo payload from GitHub. The sample was listed as released on 2022-06-28.
ThreatFabric reported that Octo was being used in the wild in 2021 and 2022 and assessed it as a rebranded evolution of ExobotCompact, tracked as ExobotCompact.D. The report attributed Octo's ownership and rental to the actor 'Architect'/'goodluck' and described its remote-access-driven on-device fraud capabilities.
Reporting on Octo distribution identified another Google Play GymDrop dropper, Pocket Screencaster, and additional campaigns using fake browser and Play Store update notices. These campaigns expanded the observed delivery methods beyond Fast Cleaner.
Cyble published analysis of a Coper sample masquerading as 'Play Store app install' with package name com.theseeye5. The report described a multi-stage infection chain, dynamic C2 infrastructure, and commands including SMS theft, keylogging, locking, overlays, and VNC control.
ThreatFabric said the Fast Cleaner campaign was active for most of February 2022 and mainly targeted European bank users in Spain, Belgium, Portugal, and Italy. BleepingComputer added that the app reached 50,000 installs before removal in February 2022.
ThreatFabric discovered a Google Play dropper named Fast Cleaner in early February 2022 and identified it as a GymDrop sample. It distributed ExobotCompact.D alongside Alien.A and Xenomorph.A.
ThreatFabric analysts observed a darknet forum post seeking the Octo Android botnet. The post was one of the anchors used to connect Octo to ExobotCompact and its rental operation.
ThreatFabric said ExobotCompact had been updated several times before the latest variant, ExobotCompact.D, appeared in November 2021. The company later linked this variant directly to Octo as part of a rebrand.
Doctor Web disclosed a new Android banking trojan family, Android.BankBot.Coper, masquerading as Bancolombia Personas and targeting users in Colombia. The malware used a modular, multi-stage infection chain with Accessibility abuse, SMS interception, phishing overlays, and anti-removal features.
Team Cymru said Coper was first observed in the wild in July 2021 targeting Colombian Android users. Early samples were distributed as a fake Bancolombia Personas application and already supported keylogging, SMS and notification interception, and screen control.
Trend Micro said it observed the DawDropper Android dropper campaign in the latter part of 2021. The campaign used Google Play apps and dynamic payload retrieval to distribute banking trojans including Octo.
BleepingComputer reported that the Exo trojan's source code leaked in 2018, a development later cited as part of Octo's lineage. Subsequent reporting suggested the Octo rebrand helped distance the malware from that leak.
ThreatFabric said Exobot was first observed in 2016 and was based on the source code of the Marcher banking trojan. It had previously targeted financial institutions in multiple countries including Turkey, France, Germany, Australia, Thailand, and Japan.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 200 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
team-cymru.com
Open sourcelabs.k7computing.com
Open sourcetrendmicro.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcethreatfabric.com
Open sourceblog.cyble.com
Open sourcenews.drweb.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.