The Android banking trojan BankBot expanded rapidly after the source code for its precursor, BankBotAlpha, and its PHP command-and-control panel were posted on a Russian forum, enabling multiple copycat variants and new campaigns. Researchers found the malware requesting Device Administrator privileges, hiding its launcher icon, intercepting and deleting SMS messages, collecting device identifiers and banking-app data, and sending stolen information to attacker-controlled servers. Early variants focused heavily on Russian and Ukrainian banks and included phishing templates for PrivatBank and Visa QIWI Wallet, while later samples broadened targeting and added stronger evasion and credential-theft capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
ESET said the Google Play BankBot dropper activity continued into November 2017 as part of a second campaign. The second campaign used additional droppers and infrastructure to deliver BankBot samples.
ESET reported two Android malware campaigns in October and November 2017 that used apps uploaded to Google Play as droppers for BankBot banking malware. The campaigns relied on malicious or trojanized apps to infect users.
Variants of BankBotAlpha appeared rapidly after the source leak and had reached VirusTotal by early January 2017. Fortinet later counted 141 variants using the same internal package name.
Fortinet reported detecting its first BankBotAlpha sample shortly after the forum leak. This marked the malware's appearance in the wild beyond the original posting.
A user named "maza-in" advertised the BankBotAlpha Android banking malware project on a Russian forum and presented it as a tutorial for building an Android banker. The post made the source code and PHP command-and-control panel publicly available.
Fortinet described BankBot as an Android banking trojan family that first surfaced in the second half of 2016. Its purpose was to steal banking credentials from Android users.
New BankBot strains later appeared in third-party APK markets and the official Google Play Store. Fortinet said these newer samples remained very similar to the code leaked in late 2016 while adding broader app injection support and call-blocking logic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcefortinet.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.