#bankingtrojan — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bankingtrojan, aggregated by home.social.
-
Grandoreiro banking trojan resurfaces in a DLL sideloading campaign that abuses Duplicate Files Finder to hit Mexico and Latin America.
#Grandoreiro #BankingTrojan #DLLSideloading #Malware #Cybersecurity #LatinAmerica
-
What the Source Leak Says About HookBot
ERMAC and HookBot are two branches of one Android banking trojan sold as a service, forking from shared code originating with Cerberus. A copy of the builder, Laravel backend, and React panel leaked in August 2025, enabling unrelated operators to deploy panels with default credentials and keys still in place. The lineage runs Cerberus to ERMAC to Hook, confirmed through source code analysis showing identical database migrations and network protocol structures. HookBot added VNC remote control and 38 new commands while maintaining ERMAC's core. The leaked source includes a Docker stack, Obfuscapk builder, and IP-whitelist firewall that hides panels but leaves the builder port exposed. Operators target 484 apps across 40+ countries including Japanese banks, Brazilian financial institutions, Turkish banks, and cryptocurrency wallets. Detection artifacts survive in builder obfuscator flags and favicons, while panel titles remain easily changed.
Pulse ID: 6a8dc2ed12d6752a7f9e258d
Pulse Link: https://otx.alienvault.com/pulse/6a8dc2ed12d6752a7f9e258d
Pulse Author: AlienVault
Created: 2026-08-25 16:29:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #BankingTrojan #Brazil #Cerber #CyberSecurity #Docker #InfoSec #Japan #Mac #OTX #OpenThreatExchange #RAT #RCE #Trojan #Turkish #VNC #bot #cryptocurrency #AlienVault
-
Discover how the new ToxicPanda Android banking trojan steals PINs and abuses accessibility features. Learn to protect your device from this malware.
#ToxicPanda #AndroidMalware #Cybersecurity #InfoSec #BankingTrojan
-
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.
Pulse ID: 6a86146ca27454b03a4cbe2d
Pulse Link: https://otx.alienvault.com/pulse/6a86146ca27454b03a4cbe2d
Pulse Author: AlienVault
Created: 2026-08-19 20:39:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
Ousaban Trojan Expands to Spain, Portugal with Advanced Evasion Tactics
Meet Ousaban, a sneaky banking Trojan that's evolved from decade-old tactics to target unsuspecting customers in Spain and Portugal, starting with a clever phishing PDF disguised as a broken file. This highly optimized threat profiles its victims before striking, making it a force to be reckoned with.
-
New Albiriox Android Malware Developed by Russian Cybercriminals https://www.securityweek.com/new-albiriox-android-malware-developed-by-russian-cybercriminals/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #Albiriox
-
New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages https://www.securityweek.com/new-sturnus-banking-trojan-targets-whatsapp-telegram-signal-messages/ #Malware&Threats #Androidtrojan #bankingtrojan #mobilemalware #malware #Sturnus
-
🚨 Alert: The new #EternidadeStealer is using WhatsApp to spread malicious files to steal banking and crypto data from users. Watch out and don’t open unexpected attachments, plus verify messages from contacts.
Read: https://hackread.com/eternidade-stealer-whatsapp-steal-banking-data/
-
77 malicious apps removed from Google Play Store https://www.malwarebytes.com/blog/news/2025/08/77-malicious-apps-removed-from-google-play-store #bankingTrojan #playstore #Android #Anatsa #News
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
Anatsa Android Banking Trojan Now Targeting 830 Financial Apps https://www.securityweek.com/anatsa-android-banking-trojan-now-targeting-830-financial-institutions/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #malware #Anatsa
-
Coyote Banking Trojan First to Abuse Microsoft UIA https://www.securityweek.com/coyote-banking-trojan-first-to-abuse-microsoft-uia/ #Malware&Threats #bankingtrojan #MicrosoftUIA #malware #stealer #Coyote
-
Coyote Banking Trojan First to Abuse Microsoft UIA https://www.securityweek.com/coyote-banking-trojan-first-to-abuse-microsoft-uia/ #Malware&Threats #bankingtrojan #MicrosoftUIA #malware #stealer #Coyote
-
Godfather Android Trojan Creates Sandbox on Infected Devices – Source: www.securityweek.com https://ciso2ciso.com/godfather-android-trojan-creates-sandbox-on-infected-devices-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Malware&Threats #securityweekcom #Androidmalware #Androidtrojan #bankingtrojan #securityweek #GodFather #Malware
-
Godfather Android Trojan Creates Sandbox on Infected Devices https://www.securityweek.com/godfather-android-trojan-creates-sandbox-on-infected-devices/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #Godfather #malware
-
Godfather Android Trojan Creates Sandbox on Infected Devices https://www.securityweek.com/godfather-android-trojan-creates-sandbox-on-infected-devices/ #Malware&Threats #Androidmalware #Androidtrojan #bankingtrojan #Godfather #malware
-
‘Crocodilus’ Android Banking Trojan Allows Device Takeover, Data Theft – Source: www.securityweek.com https://ciso2ciso.com/crocodilus-android-banking-trojan-allows-device-takeover-data-theft-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Malware&Threats #securityweekcom #Androidmalware #bankingtrojan #securityweek #Crocodilus #Malware
-
‘Crocodilus’ Android Banking Trojan Allows Device Takeover, Data Theft https://www.securityweek.com/crocodilus-android-banking-trojan-allows-device-takeover-data-theft/ #Malware&Threats #Androidmalware #bankingtrojan #Crocodilus #malware
-
‘Crocodilus’ Android Banking Trojan Allows Device Takeover, Data Theft https://www.securityweek.com/crocodilus-android-banking-trojan-allows-device-takeover-data-theft/ #Malware&Threats #Androidmalware #bankingtrojan #Crocodilus #malware
-
Fresh Grandoreiro Banking Trojan Campaigns Target Latin America, Europe – Source: www.securityweek.com https://ciso2ciso.com/fresh-grandoreiro-banking-trojan-campaigns-target-latin-america-europe-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Malware&Threats #securityweekcom #bankingtrojan #securityweek #Grandoreiro #Malware #Trojan
-
Fresh Grandoreiro Banking Trojan Campaigns Target Latin America, Europe https://www.securityweek.com/fresh-grandoreiro-banking-trojan-campaigns-target-latin-america-europe/ #Malware&Threats #bankingtrojan #Grandoreiro #malware #trojan
-
Ursnif Trojan Campaign Targets U.S. Professionals via Stealthy Spam Attacks https://thecyberexpress.com/ursnif-banking-trojan/ #TheCyberExpressNews #UrsnifBankingTrojan #TheCyberExpress #FirewallDaily #bankingtrojan #Ursniftrojan #DarkWebNews #CyberNews
-
Hidden in Plain Sight: ErrorFather’s Deadly Deployment of Cerberus – Source:cyble.com https://ciso2ciso.com/hidden-in-plain-sight-errorfathers-deadly-deployment-of-cerberus-sourcecyble-com/ #BankingTrojan #ErrorFather #CybleBlog #'Cyber
-
Hidden in Plain Sight: ErrorFather’s Deadly Deployment of Cerberus https://cyble.com/blog/hidden-in-plain-sight-errorfathers-deadly-deployment-of-cerberus/ #BankingTrojan #ErrorFather
-
Cyble Honeypot Sensors Detect WordPress Plugin Attack, New Banking Trojan https://cyble.com/blog/cyble-honeypot-sensors-detect-wordpress-plugin-attack-new-banking-trojan/ #BankingTrojan #Vulnerability #WordPress #Honeypot
-
Coyote Banking Trojan Attacking Windows Users To Steal Login Details https://gbhackers.com/coyote-banking-trojan-windows-attack/ #BankingTrojan #cybersecurity #LatinAmerica #CyberAttack #Phishing #Malware
-
Mekotio Banking Trojan Attacking American Users To Steal Financial Data https://gbhackers.com/mekotio-banking-trojan-american-attacks/ #CyberSecurityNews #cybersecurity #EmailSecurity #BankingTrojan #Phishing #phishing #Malware #Mekotio