CERT-AgID published a reverse-engineering analysis of Coper, an Android banking trojan built to compromise mobile devices through a small loader APK and a native library that decrypts and loads an additional DEX payload at runtime. The malware requests broad Android permissions and abuses Accessibility Service, Device Admin, SMS access, notification access, and background execution to steal messages and notifications, capture credentials through injects and keylogging, lock infected devices, and maintain persistence on the handset.
The analysis found that Coper communicates with multiple hard-coded command-and-control domains over HTTP POST, protecting JSON data with AES-128-ECB while using RC4 to decrypt components embedded in the app. Operators can issue commands to enable banking injects, send SMS messages, place calls, uninstall applications, suppress notifications, activate VNC-like remote control, and remove the malware itself. CERT-AgID also reported that some intrusive functions are delayed until after initial registration with the C2 infrastructure, suggesting the attackers selectively activate capabilities based on victim language or geography.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
CERT-AgID identified the analyzed sample of the Android banking malware Coper in May 2022. The sample was later used for a technical reverse-engineering analysis of its loader, dynamic DEX decryption, permissions abuse, and C2 communications.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.