Security researchers reported multiple Android malware campaigns that used droppers distributed through Google Play to install banking trojans and remote-access malware while evading marketplace defenses. Check Point detailed Clast82, a dropper embedded in trojanized utility apps that delayed malicious activity until after publication by checking a Firebase-controlled enable flag, then fetched payloads from GitHub and pushed victims to allow installs from unknown sources through repeated fake Google Play Services prompts. The campaign delivered AlienBot Banker and MRAT, relied on fake developer accounts and shared infrastructure, and led to the removal of the identified apps from Google Play.
Trend Micro later described DawDropper as a similar Android dropper operation that also abused Firebase Realtime Database and GitHub to dynamically retrieve payloads and avoid detection in apps posing as document scanners, cleaners, and QR scanners. DawDropper was used to distribute banking malware including Octo, Hydra, Ermac, and TeaBot; researchers said Octo could steal banking credentials, intercept SMS messages, disable Google Play Protect, hijack devices, and use VNC-based remote screen control while hiding its activity. The findings also tied these campaigns to a broader underground market for dropper-as-a-service (DaaS) offerings, showing how commodity delivery infrastructure was being used to scale Android banking malware distribution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Trend Micro's IOC list included the DawDropper sample com.scando.qukscanner, detected as AndroidOS_DawDropper.HRX, which used a Firebase database and downloaded an Octo payload from raw.githubusercontent.com.
Trend Micro's IOC list included the DawDropper sample com.casualplay.leadbro, detected as AndroidOS_DawDropper.HRXA, which used a Firebase database and downloaded a Hydra payload from GitHub.
Trend Micro said it observed the DawDropper Android banking malware dropper campaign in the latter part of 2021. The dropper was used in Google Play apps to distribute Octo, Hydra, Ermac, and TeaBot.
Trend Micro said the Vultur dropper, also known as Brunhilda, was first reported as a dropper-as-a-service offering at the end of 2020.
Trend Micro reported the DawDropper campaign and said the malicious apps masquerading as utilities such as document scanners and cleaners were no longer available on Google Play by the time of reporting.
By February 9, Google confirmed that all identified Clast82 applications had been removed from the Google Play Store.
Check Point Research reported the Clast82 campaign to Google on January 28 after identifying the malicious Google Play apps and their payload delivery infrastructure.
Check Point Research said it initially discovered the Clast82 Android dropper campaign on Google Play on January 27. The campaign used trojanized apps to deliver AlienBot Banker and MRAT payloads.
3 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourceresearch.checkpoint.com
Open sourceprodaft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.