Researchers identified a new Svpeng Android banking trojan variant, Trojan-Banker.AndroidOS.Svpeng.ae, that expanded the malware family’s capabilities by abusing Android accessibility services to capture keystrokes and other user activity. The malware can grant itself broad privileges, hinder removal, steal text entered into other applications, take screenshots, display phishing overlays on targeted apps, and receive commands from a command-and-control server.
The campaign was observed in limited volumes across 23 countries, with the largest shares in Russia, Germany, and Turkey, although the malware was designed not to run on devices using the Russian language setting. The sample was distributed through malicious websites posing as a fake Flash Player update, and researchers said the technique remained effective even against fully updated Android devices.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Over one observed week in mid-July 2017, researchers saw a small number of users attacked by the new Svpeng.ae variant across 23 countries. The highest shares of victims were in Russia, Germany, and Turkey, while the malware avoided running on devices set to Russian language.
In mid-July 2017, researchers identified Trojan-Banker.AndroidOS.Svpeng.ae, a new Svpeng variant for Android. The variant added keylogging by abusing Android accessibility services and could steal entered text, take screenshots, resist uninstallation, and deploy phishing overlays.
In 2016, attackers actively distributed Svpeng through AdSense by exploiting a Chrome browser vulnerability. This marked an earlier distribution campaign for the malware family before the newly analyzed variant appeared.
The Svpeng mobile malware family has been active since at least 2013 and was among the first families to target SMS banking. It also previously used phishing overlays and device-locking extortion tactics.
Researchers intercepted and decrypted an encrypted configuration file delivered from the malware's command-and-control server. The configuration revealed targeted apps, phishing URLs, antivirus apps the Trojan tried to block, and supported commands for SMS theft, contact collection, call-log collection, and URL opening.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.