Tag: Android Trojan

New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices
News

New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices

Details of a new Android banking malware known as Sturnus, which permits credential theft and complete device takeover to carry out financial crime, have been revealed by cybersecurity researchers. According to a research provided with The Hacker News by ThreatFabric, one of its main differentiators is its capacity to get beyond encrypted messaging. Sturnus can keep an eye on WhatsApp, Telegram, and Signal conversations by immediately recording content from the device screen after decryption. Its capacity to stage overlay assaults by displaying phony login windows atop banking apps in order to obtain victims' credentials is another noteworthy capability. The Dutch mobile security firm claims that Sturnus is privately run and is in the evaluation phase. The following is a list of art...
Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers
News

Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers

Details of a new Android remote access trojan (RAT) named Fantasy Hub, which is marketed on Russian-speaking Telegram channels through a Malware-as-a-Service (MaaS) model, have been revealed by cybersecurity researchers. The seller claims that the malware facilitates device control and surveillance, enabling malicious actors to gather SMS messages, contacts, call logs, images, and videos, as well as intercept, respond to, and eliminate incoming notifications. Zimperium researcher Vishnu Pratapagiri noted in a report last week that it is a MaaS product featuring seller documentation, videos, and a bot-driven subscription model that offers novice attackers a low barrier to entry. It poses a direct threat to enterprise customers using BYOD and any organization whose employees rely o...
New Android Trojan ‘Herodotus’ Outsmarts Anti Fraud Systems by Typing Like a Human
News

New Android Trojan ‘Herodotus’ Outsmarts Anti Fraud Systems by Typing Like a Human

Researchers studying cybersecurity have revealed information on Herodotus, a new Android banking malware that has been seen in active efforts to carry out device takeover (DTO) assaults against Brazil and Italy. According to a study provided to The Hacker News by ThreatFabric, Herodotus is made to take control of devices while initially attempting to imitate human behavior and evade behavior biometric detection. According to the Dutch security firm, on September 7, 2025, the Trojan was first promoted in underground forums under the malware-as-a-service (MaaS) paradigm, claiming to be compatible with Android 9–16 devices. Although the malware does not directly evolve from previous financial malware called Brokewell, it does seem to have borrowed some of its components to create th...
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events
News

New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events

Researchers studying cybersecurity have discovered Datzbro, an Android banking malware that was previously unknown. It can make fraudulent transactions by preying on the elderly and carry out device takeover (DTO) assaults. ThreatFabric, a Dutch mobile security company, said that it learned about the effort in August 2025 when Australian consumers reported scammers running Facebook groups that advertised active senior travel. Singapore, Malaysia, Canada, South Africa, and the United Kingdom are among the other countries that the threat actors have targeted. It further stated that the efforts were especially targeted at senior citizens seeking out social gatherings, travel, face-to-face meetings, and the like. It has been discovered that these Facebook groups, which purport to plan d...
TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud
News

TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud

TrickMo is a new version of an Android banking trojan that cybersecurity experts have discovered. It has several new features, including the ability to present phony login windows in order to grab victims' banking credentials and avoid examination. Among the methods include utilizing JSONPacker in conjunction with corrupted ZIP files, Michele Roviello and Alessandro Strino, researchers on Cleafy security, said. "In addition, the application is installed through a dropper app that shares the same anti-analysis mechanisms." These characteristics are intended to avoid discovery and obstruct cybersecurity experts' attempts to dissect and lessen the infection read more about TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud. Get up to date on the lates...
Beware of SpyNote Android Trojan that Records Audio and Phone Calls
News

Beware of SpyNote Android Trojan that Records Audio and Phone Calls

We've deconstructed the Android banking trojan, known as SpyNote, to expose its many information-gathering capabilities. According to F-Secure, attack chains incorporating the spyware typically propagate through SMS phishing campaigns, tricking potential victims into installing the program by clicking on the linked link. In an effort to make it more difficult to be discovered, SpyNote is notorious for concealing its existence from the Recents and Android home screens in addition to seeking intrusive permissions to access call logs, cameras, SMS messages, and external storage. According to a study released last week by F-Secure researcher Amit Tambe, "the SpyNote malware app can be launched via an external trigger read more Beware of SpyNote Android Trojan that Records Audio and ...
GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries
News

GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries

A new Android banking trojan known as GoldDigger has been discovered that targets multiple financial applications with the intention of stealing victims' money and infecting devices with a backdoor. "The malware targets more than 50 Vietnamese banking, e-wallet, and cryptocurrency wallet applications," Group-IB reported. There are signs that this threat may be about to spread to countries that speak Spanish and the larger APAC area. Although there is evidence to imply that the malware has been active since June 2023, the Singapore-based company just discovered it in August 2023 read more GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of ...
New Android Banking Trojan Nexus Promoted As MaaS
News

New Android Banking Trojan Nexus Promoted As MaaS

A brand-new Android banking Trojan has been found in a number of worldwide harmful activities.  The programme, dubbed "Nexus" by Cleafy security experts, offers functionality to conduct account takeover (ATO) assaults and is advertised as a component of a Malware-as-a-Service (MaaS) subscription. The organisation stated in a Tuesday advisory that "a new Android banking Malware debuted on several hacking forums under the name of Nexus" in January 2023.  ...