A new Android banking Trojan known as Klopatra has emerged, targeting users in Europe with sophisticated techniques to hijack bank accounts. Security researchers have identified Klopatra as a highly evasive malware that leverages hidden VNC (Virtual Network Computing) functionality to remotely control infected devices without the victim’s knowledge. The Trojan is capable of bypassing security barriers and executing fraudulent bank transfers while users are asleep, making detection and prevention particularly challenging. Klopatra employs commercial-grade obfuscation methods to evade antivirus and security solutions, increasing its persistence on compromised devices. Initial infections were observed as early as March, with a significant uptick in activity during the summer, resulting in over 3,000 confirmed infections across Italy and Spain. The malware is distributed through deceptive lures, including fake streaming service applications, which entice users to install malicious APK files. Once installed, Klopatra can intercept SMS messages, steal authentication codes, and manipulate banking applications to initiate unauthorized transactions. The Trojan’s hidden VNC capability allows attackers to interact with the device in real time, mimicking legitimate user behavior and circumventing security controls such as two-factor authentication. Victims are often unaware of the compromise, as the malware suppresses notifications and operates silently in the background. Security experts warn that Klopatra’s modular architecture enables rapid adaptation to new security measures and banking app updates. The campaign’s focus on European financial institutions highlights a growing trend of region-specific targeting by mobile malware operators. Researchers emphasize the importance of user education, robust mobile security solutions, and vigilance against unsolicited app installations to mitigate the risk posed by Klopatra. Financial organizations are advised to monitor for anomalous transactions and strengthen fraud detection mechanisms. The emergence of Klopatra underscores the evolving threat landscape for Android users, particularly in the context of mobile banking. Law enforcement and cybersecurity agencies are collaborating to track the distribution infrastructure and disrupt the operators behind the campaign. The use of commercial obfuscation tools by Klopatra sets a new standard for mobile malware stealth, complicating efforts to analyze and remediate infections. The incident serves as a reminder of the critical need for continuous monitoring and rapid response capabilities in the face of advanced mobile threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.