home.social

#bankingtrojan — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bankingtrojan, aggregated by home.social.

  1. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  2. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  3. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  4. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  5. Uncovering StreamRat: From Meta Ads to Full Device Takeover

    ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications.

    Pulse ID: 6a9826f869eb70a6b15298ec
    Pulse Link: otx.alienvault.com/pulse/6a982
    Pulse Author: AlienVault
    Created: 2026-09-02 13:39:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #BankingTrojan #CyberSecurity #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #SMS #Spain #ThreatFabric #Trojan #VNC #VPN #bot #AlienVault

  6. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault