Doctor Web disclosed a new Android banking trojan family, Android.BankBot.Coper, that masqueraded as the official Bancolombia Personas app and targeted users in Colombia. The malware used a modular, multi-stage infection chain in which a dropper decrypted and installed additional components, abused Android Accessibility Services for device control, attempted to disable Google Play Protect, and deployed its main payload disguised as a system app named Cache plugin.
Once active, Coper maintained contact with command-and-control servers and supported banking fraud and device takeover functions including phishing overlays, interception of notifications and SMS messages, sending SMS and USSD requests, keylogging, and lock-screen manipulation. Doctor Web also reported strong self-protection features that monitored attempts to uninstall the app or revoke privileges and simulated button presses to block removal; published IoCs linked the campaign to malicious APKs, DEX files, package names, domains such as sportsstyle.club, fitnessstyle.xyz, and 4-u.wtf, and IP addresses 18.217.36.170 and 45.76.35.31.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Doctor Web publicly disclosed a newly discovered Android banking trojan family named Android.BankBot.Coper. The report said known samples masqueraded as the Bancolombia Personas app and targeted users in Colombia using a modular, multi-stage infection chain with anti-removal features.
A GitHub commit attributed to Ivan Korolev added new indicators of compromise for the Android.BankBot.Coper banking trojan, including sample hashes, package names, domains, and IP addresses linked to the campaign targeting Colombian users.
Dr.Web added detection for Android.BankBot.Coper.2 to its virus database. The malware encyclopedia entry identifies it as an Android banking trojan distributed by the Coper.1 dropper and disguised as a system app called Cache plugin.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
news.drweb.com
Open sourcenews.drweb.ru
Open sourcegithub.com
Open sourcevms.drweb.com
Open sourcevms.drweb.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.