#bankingtrojan — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bankingtrojan, aggregated by home.social.
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
Astaroth's new WhatsApp spambot auto-messages every victim contact in Brazil using a hidden browser, quietly turning each victim into a malware distributor.
#Astaroth #WhatsApp #BrazilMalware #BankingTrojan #LATAM
https://securityonline.info/astaroth-whatsapp-spambot/?utm_source=mastodon&utm_medium=jetpack_social
-
Astaroth's new WhatsApp spambot auto-messages every victim contact in Brazil using a hidden browser, quietly turning each victim into a malware distributor.
#Astaroth #WhatsApp #BrazilMalware #BankingTrojan #LATAM
https://securityonline.info/astaroth-whatsapp-spambot/?utm_source=mastodon&utm_medium=jetpack_social
-
The GoldPickaxe banking Trojan returns, stealing biometric data, SMS, and lock screens from Android users across Asia, Zimperium warns.
#GoldPickaxe #GoldFactory #BankingTrojan #Android #CyberSecurity
http://securityonline.info/goldpickaxe-banking-trojan/?utm_source=mastodon&utm_medium=jetpack_social
-
The GoldPickaxe banking Trojan returns, stealing biometric data, SMS, and lock screens from Android users across Asia, Zimperium warns.
#GoldPickaxe #GoldFactory #BankingTrojan #Android #CyberSecurity
http://securityonline.info/goldpickaxe-banking-trojan/?utm_source=mastodon&utm_medium=jetpack_social
-
Albiriox malware spreads via a fake UniCredit reward and a Telegram bot. The Android banking trojan abuses Accessibility to steal OTPs and hijack devices.
#Albiriox #AndroidMalware #BankingTrojan #UniCredit #Telegram
-
Albiriox malware spreads via a fake UniCredit reward and a Telegram bot. The Android banking trojan abuses Accessibility to steal OTPs and hijack devices.
#Albiriox #AndroidMalware #BankingTrojan #UniCredit #Telegram
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
FortiGuard Labs discovered a new Ousaban banking trojan campaign. The attackers use geo-blocking to target banking users in Spain and Portugal.
-
FortiGuard Labs discovered a new Ousaban banking trojan campaign. The attackers use geo-blocking to target banking users in Spain and Portugal.
-
Ousaban Trojan Expands to Spain, Portugal with Advanced Evasion Tactics
Meet Ousaban, a sneaky banking Trojan that's evolved from decade-old tactics to target unsuspecting customers in Spain and Portugal, starting with a clever phishing PDF disguised as a broken file. This highly optimized threat profiles its victims before striking, making it a force to be reckoned with.
-
📰 New TCLBANKER Trojan Spreads via WhatsApp and Outlook, Targeting 59 Brazilian Financial Apps
🇧🇷 New Banking Trojan 'TCLBANKER' targets 59 Brazilian financial apps! The malware spreads like a worm via WhatsApp & Outlook, using DLL side-loading to evade detection. Stay vigilant! 💻 #Malware #BankingTrojan #Brazil #Cybersecurity
🌐 cyber[.]netsecops[.]io
-
📰 New TCLBANKER Trojan Spreads via WhatsApp and Outlook, Targeting 59 Brazilian Financial Apps
🇧🇷 New Banking Trojan 'TCLBANKER' targets 59 Brazilian financial apps! The malware spreads like a worm via WhatsApp & Outlook, using DLL side-loading to evade detection. Stay vigilant! 💻 #Malware #BankingTrojan #Brazil #Cybersecurity
🌐 cyber[.]netsecops[.]io
-
📰 Grandoreiro Banking Trojan Resurges, Targeting Banks in Spain and Latin America
Grandoreiro banking trojan is back. 📈 New campaigns are targeting banks and customers in Spain and Latin America, using phishing and DLL side-loading to steal credentials with fake overlays. 🏦 #Grandoreiro #Malware #BankingTrojan #Phishing #Fintech
🌐 cyber[.]netsecops[.]io
-
Banking Trojan Targets Crypto Firms with Sophisticated Attacks
A new banking Trojan, dubbed TCLBanker, is wreaking havoc on crypto and finance platforms, allowing hackers to remotely control infected systems and steal sensitive info. This sophisticated attack, linked to North Korea's notorious Lazarus Group, has already led to the largest crypto platform hack of 2026.
#Tclbanker #BankingTrojan #LazarusGroup #NorthKorea #CryptoFirms
-
New Albiriox Android Malware Developed by Russian Cybercriminals https://www.securityweek.com/new-albiriox-android-malware-developed-by-russian-cybercriminals/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #Albiriox
-
New Albiriox Android Malware Developed by Russian Cybercriminals https://www.securityweek.com/new-albiriox-android-malware-developed-by-russian-cybercriminals/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #Albiriox
-
New Albiriox Android Malware Developed by Russian Cybercriminals https://www.securityweek.com/new-albiriox-android-malware-developed-by-russian-cybercriminals/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #Albiriox
-
New Albiriox Android Malware Developed by Russian Cybercriminals https://www.securityweek.com/new-albiriox-android-malware-developed-by-russian-cybercriminals/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #Albiriox
-
New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages https://www.securityweek.com/new-sturnus-banking-trojan-targets-whatsapp-telegram-signal-messages/ #Malware&Threats #Androidtrojan #bankingtrojan #mobilemalware #malware #Sturnus
-
New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages https://www.securityweek.com/new-sturnus-banking-trojan-targets-whatsapp-telegram-signal-messages/ #Malware&Threats #Androidtrojan #bankingtrojan #mobilemalware #malware #Sturnus
-
New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages https://www.securityweek.com/new-sturnus-banking-trojan-targets-whatsapp-telegram-signal-messages/ #Malware&Threats #Androidtrojan #bankingtrojan #mobilemalware #malware #Sturnus
-
New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages https://www.securityweek.com/new-sturnus-banking-trojan-targets-whatsapp-telegram-signal-messages/ #Malware&Threats #Androidtrojan #bankingtrojan #mobilemalware #malware #Sturnus
-
🚨 Alert: The new #EternidadeStealer is using WhatsApp to spread malicious files to steal banking and crypto data from users. Watch out and don’t open unexpected attachments, plus verify messages from contacts.
Read: https://hackread.com/eternidade-stealer-whatsapp-steal-banking-data/
-
🚨 Alert: The new #EternidadeStealer is using WhatsApp to spread malicious files to steal banking and crypto data from users. Watch out and don’t open unexpected attachments, plus verify messages from contacts.
Read: https://hackread.com/eternidade-stealer-whatsapp-steal-banking-data/
-
🚨 Alert: The new #EternidadeStealer is using WhatsApp to spread malicious files to steal banking and crypto data from users. Watch out and don’t open unexpected attachments, plus verify messages from contacts.
Read: https://hackread.com/eternidade-stealer-whatsapp-steal-banking-data/
-
🚨 Alert: The new #EternidadeStealer is using WhatsApp to spread malicious files to steal banking and crypto data from users. Watch out and don’t open unexpected attachments, plus verify messages from contacts.
Read: https://hackread.com/eternidade-stealer-whatsapp-steal-banking-data/
-
🚨 Alert: The new #EternidadeStealer is using WhatsApp to spread malicious files to steal banking and crypto data from users. Watch out and don’t open unexpected attachments, plus verify messages from contacts.
Read: https://hackread.com/eternidade-stealer-whatsapp-steal-banking-data/
-
Android malware alert: Mobdro Pro IP TV + VPN installs Klopatra banking Trojan, compromising devices and banking credentials.
More info: https://www.technadu.com/fake-vpn-spreads-malware-targeting-android-banking-accounts/611164/
#AndroidSecurity #CyberSecurity #BankingTrojan #MobileSecurity #VPN #TechNadu
-
Android malware alert: Mobdro Pro IP TV + VPN installs Klopatra banking Trojan, compromising devices and banking credentials.
More info: https://www.technadu.com/fake-vpn-spreads-malware-targeting-android-banking-accounts/611164/
#AndroidSecurity #CyberSecurity #BankingTrojan #MobileSecurity #VPN #TechNadu
-
Android malware alert: Mobdro Pro IP TV + VPN installs Klopatra banking Trojan, compromising devices and banking credentials.
More info: https://www.technadu.com/fake-vpn-spreads-malware-targeting-android-banking-accounts/611164/
#AndroidSecurity #CyberSecurity #BankingTrojan #MobileSecurity #VPN #TechNadu
-
77 malicious apps removed from Google Play Store https://www.malwarebytes.com/blog/news/2025/08/77-malicious-apps-removed-from-google-play-store #bankingTrojan #playstore #Android #Anatsa #News
-
77 malicious apps removed from Google Play Store https://www.malwarebytes.com/blog/news/2025/08/77-malicious-apps-removed-from-google-play-store #bankingTrojan #playstore #Android #Anatsa #News
-
77 malicious apps removed from Google Play Store https://www.malwarebytes.com/blog/news/2025/08/77-malicious-apps-removed-from-google-play-store #bankingTrojan #playstore #Android #Anatsa #News
-
77 malicious apps removed from Google Play Store https://www.malwarebytes.com/blog/news/2025/08/77-malicious-apps-removed-from-google-play-store #bankingTrojan #playstore #Android #Anatsa #News
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
ERMAC V3.0's source code leak reveals a crafty banking trojan overlaying fake forms on trusted apps—and its glaring vulnerabilities could reshape cyber defenses. How safe are your apps?
#ermacv3
#androidmalware
#cybersecurity
#bankingtrojan
#malwareanalysis -
ERMAC V3.0's source code leak reveals a crafty banking trojan overlaying fake forms on trusted apps—and its glaring vulnerabilities could reshape cyber defenses. How safe are your apps?
#ermacv3
#androidmalware
#cybersecurity
#bankingtrojan
#malwareanalysis -
ERMAC V3.0's source code leak reveals a crafty banking trojan overlaying fake forms on trusted apps—and its glaring vulnerabilities could reshape cyber defenses. How safe are your apps?
#ermacv3
#androidmalware
#cybersecurity
#bankingtrojan
#malwareanalysis -
Coyote Banking Trojan First to Abuse Microsoft UIA https://www.securityweek.com/coyote-banking-trojan-first-to-abuse-microsoft-uia/ #Malware&Threats #bankingtrojan #MicrosoftUIA #malware #stealer #Coyote
-
Coyote Banking Trojan First to Abuse Microsoft UIA https://www.securityweek.com/coyote-banking-trojan-first-to-abuse-microsoft-uia/ #Malware&Threats #bankingtrojan #MicrosoftUIA #malware #stealer #Coyote
-
Coyote Banking Trojan First to Abuse Microsoft UIA https://www.securityweek.com/coyote-banking-trojan-first-to-abuse-microsoft-uia/ #Malware&Threats #bankingtrojan #MicrosoftUIA #malware #stealer #Coyote
-
Coyote Banking Trojan First to Abuse Microsoft UIA https://www.securityweek.com/coyote-banking-trojan-first-to-abuse-microsoft-uia/ #Malware&Threats #bankingtrojan #MicrosoftUIA #malware #stealer #Coyote
-
Coyote Banking Trojan First to Abuse Microsoft UIA https://www.securityweek.com/coyote-banking-trojan-first-to-abuse-microsoft-uia/ #Malware&Threats #bankingtrojan #MicrosoftUIA #malware #stealer #Coyote
-
Coyote Banking Trojan First to Abuse Microsoft UIA https://www.securityweek.com/coyote-banking-trojan-first-to-abuse-microsoft-uia/ #Malware&Threats #bankingtrojan #MicrosoftUIA #malware #stealer #Coyote