The S.O.V.A. Android malware has been documented as a banking trojan and botnet under active development, with samples masquerading as legitimate apps including Adobe Flash Player and Minecraft. Researchers found it targets Android 7 through 11, relies heavily on abused Accessibility, notification listener, and default SMS permissions, and performs regional exclusion checks to avoid devices associated with CIS countries. Once launched, it can register infected devices with command-and-control infrastructure, start multiple background services, hide itself from the app list, resist device locking, and evade analysis through anti-emulation checks.
S.O.V.A. is designed to steal a wide range of data, including banking credentials, cookies, SMS messages, push notifications, clipboard contents, and keystrokes, while also overlaying fake login pages on banking and cryptocurrency applications. Analysis of newer samples showed added botnet-style behavior such as cryptocurrency clipboard hijacking, root-status reporting, encrypted logging using Base64-wrapped RC4, and Retrofit2-based C2 communications, alongside previously observed support for hidden notification interception, SMS sending, and DDoS-related commands. Researchers also noted the malware’s roadmap included broader Android version support, MiTM, ransomware, VNC, Telegram-based C2, and more automated injection features.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
A later analyzed S.O.V.A sample masqueraded as a Minecraft application and was found to be packed and implemented in Kotlin. The sample performed CIS-related exclusion checks, anti-emulation checks, requested accessibility permissions, registered with its C2, and used services for clipboard hijacking, device-state monitoring, SMS interaction, and hiding itself from the app list.
Cyble Research Labs identified the S.O.V.A advertisement during threat hunting and analyzed an APK masquerading as Adobe Flash Player. The analysis documented its abuse of Accessibility, notification listener, and default SMS app permissions, credential-stealing overlays, cookie theft, clipboard capture, SMS abuse, DDoS capability, and C2 communications with xsph[.]ru infrastructure.
An unknown threat actor posted an advertisement for the Android banking trojan S.O.V.A. on the XSS.is forum, describing the malware as under active development. The actor said it currently supported Android 7 through 11 and planned features including Android 12 support, man-in-the-middle, ransomware, and Telegram-based C2.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.