Trusted Design

BankBot Found on Google Play and Targets Ten New UAE Banking Apps

概要

The Android-targeting BankBot malware (all variants detected by Trend Micro as ANDROIDOS_BANKBOT) first surfaced January of this year and is reportedly the improved version of an unnamed open source banking malware that was leaked in an underground hacking forum. BankBot is particularly risky because it disguises itself as legitimate banking apps, typically using fake overlay screens to mimic existing banking apps and steal user credentials. BankBot is also capable of hijacking and intercepting SMS messages, which means that it can bypass SMS-based 2-factor authentication. Throughout the year, Bankbot has been distributed as benign apps, some of which made their way onto popular app stores. In April and July of 2017, Bankbot-infected apps were detected posing as entertainment and online banking apps on Google Play. More than twenty were found and exposed during the said months.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Dragonfly

Score: 3.78
Matched TTPs:
  • T1113 - Screen Capture
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

BRONZE BUTLER

Score: 7.62
Matched TTPs:
  • T1113 - Screen Capture
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Gamaredon Group

Score: 8.84
Matched TTPs:
  • T1113 - Screen Capture
  • T1583.006 - Web Services
  • T1001 - Data Obfuscation
MITREへのリンク →

OilRig

Score: 16.23
Matched TTPs:
  • T1113 - Screen Capture
  • T1027.005 - Indicator Removal from Tools
  • T1203 - Exploitation for Client Execution
  • T1555.004 - Windows Credential Manager
  • T1588.003 - Code Signing Certificates
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT28

Score: 13.36
Matched TTPs:
  • T1113 - Screen Capture
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1598 - Phishing for Information
  • T1550.001 - Application Access Token
MITREへのリンク →

MoustachedBouncer

Score: 6.82
Matched TTPs:
  • T1113 - Screen Capture
  • T1659 - Content Injection
MITREへのリンク →

Magic Hound

Score: 12.54
Matched TTPs:
  • T1113 - Screen Capture
  • T1087.003 - Email Account
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

MuddyWater

Score: 5.79
Matched TTPs:
  • T1113 - Screen Capture
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Winter Vivern

Score: 4.38
Matched TTPs:
  • T1113 - Screen Capture
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Kimsuky

Score: 24.07
Matched TTPs:
  • T1113 - Screen Capture
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1055.012 - Process Hollowing
  • T1218.010 - Regsvr32
  • T1598 - Phishing for Information
  • T1588.003 - Code Signing Certificates
  • T1078.003 - Local Accounts
MITREへのリンク →

Dark Caracal

Score: 4.81
Matched TTPs:
  • T1113 - Screen Capture
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN7

Score: 13.60
Matched TTPs:
  • T1113 - Screen Capture
  • T1674 - Input Injection
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1078.003 - Local Accounts
MITREへのリンク →

TA505

Score: 3.62
Matched TTPs:
  • T1087.003 - Email Account
MITREへのリンク →

RedCurl

Score: 3.62
Matched TTPs:
  • T1087.003 - Email Account
MITREへのリンク →

Sandworm Team

Score: 5.12
Matched TTPs:
  • T1087.003 - Email Account
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT29

Score: 12.54
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
  • T1078.003 - Local Accounts
MITREへのリンク →

APT32

Score: 14.86
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

FIN13

Score: 9.16
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1556 - Modify Authentication Process
MITREへのリンク →

Wizard Spider

Score: 8.87
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1555.004 - Windows Credential Manager
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

BITTER

Score: 3.59
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

FIN6

Score: 4.62
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

PROMETHIUM

Score: 8.89
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
  • T1078.003 - Local Accounts
MITREへのリンク →

UNC3886

Score: 10.87
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
  • T1027.005 - Indicator Removal from Tools
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

ZIRCONIUM

Score: 7.55
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1598 - Phishing for Information
MITREへのリンク →

Higaisa

Score: 7.43
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1001.003 - Protocol or Service Impersonation
MITREへのリンク →

Lazarus Group

Score: 16.10
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1001.003 - Protocol or Service Impersonation
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Storm-0501

Score: 7.36
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
MITREへのリンク →

APT41

Score: 3.59
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Contagious Interview

Score: 7.06
Matched TTPs:
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Scattered Spider

Score: 5.96
Matched TTPs:
  • T1657 - Financial Theft
  • T1598 - Phishing for Information
MITREへのリンク →

Medusa Group

Score: 4.54
Matched TTPs:
  • T1657 - Financial Theft
  • T1583.006 - Web Services
MITREへのリンク →

Play

Score: 5.19
Matched TTPs:
  • T1657 - Financial Theft
  • T1078.003 - Local Accounts
MITREへのリンク →

HAFNIUM

Score: 8.81
Matched TTPs:
  • T1583.006 - Web Services
  • T1550.001 - Application Access Token
  • T1078.003 - Local Accounts
MITREへのリンク →

Mustang Panda

Score: 14.63
Matched TTPs:
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1001.003 - Protocol or Service Impersonation
  • T1588.003 - Code Signing Certificates
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Turla

Score: 11.45
Matched TTPs:
  • T1583.006 - Web Services
  • T1027.005 - Indicator Removal from Tools
  • T1555.004 - Windows Credential Manager
  • T1078.003 - Local Accounts
MITREへのリンク →

Confucius

Score: 3.51
Matched TTPs:
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Saint Bear

Score: 3.51
Matched TTPs:
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

TA2541

Score: 5.16
Matched TTPs:
  • T1583.006 - Web Services
  • T1055.012 - Process Hollowing
MITREへのリンク →

Patchwork

Score: 7.80
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
  • T1055.012 - Process Hollowing
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Deep Panda

Score: 5.90
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
  • T1218.010 - Regsvr32
MITREへのリンク →

GALLIUM

Score: 3.15
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
MITREへのリンク →

APT3

Score: 4.65
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Gorgon Group

Score: 3.15
Matched TTPs:
  • T1055.012 - Process Hollowing
MITREへのリンク →

Threat Group-3390

Score: 7.80
Matched TTPs:
  • T1055.012 - Process Hollowing
  • T1203 - Exploitation for Client Execution
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

BlackByte

Score: 3.15
Matched TTPs:
  • T1055.012 - Process Hollowing
MITREへのリンク →

menuPass

Score: 3.15
Matched TTPs:
  • T1055.012 - Process Hollowing
MITREへのリンク →

Cobalt Group

Score: 4.24
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Leviathan

Score: 4.24
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Inception

Score: 4.24
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

EXOTIC LILY

Score: 4.02
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BlackTech

Score: 4.65
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Sea Turtle

Score: 4.16
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

Tropic Trooper

Score: 4.16
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

Moonstone Sleet

Score: 5.96
Matched TTPs:
  • T1598 - Phishing for Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Stealth Falcon

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

FIN8

Score: 3.15
Matched TTPs:
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.75
Matched TTPs:
  • T1113 - Screen Capture
  • T1078.003 - Local Accounts
  • T1598 - Phishing for Information
  • T1588.003 - Code Signing Certificates
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1055.012 - Process Hollowing
  • T1583.006 - Web Services
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Lazarus Group

Score: 0.55
Matched TTPs:
  • T1001.003 - Protocol or Service Impersonation
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1203 - Exploitation for Client Execution
  • T1583.006 - Web Services
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

FIN7

Score: 0.55
Matched TTPs:
  • T1113 - Screen Capture
  • T1078.003 - Local Accounts
  • T1674 - Input Injection
  • T1583.006 - Web Services
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

OilRig

Score: 0.55
Matched TTPs:
  • T1113 - Screen Capture
  • T1027.005 - Indicator Removal from Tools
  • T1588.003 - Code Signing Certificates
  • T1555.004 - Windows Credential Manager
  • T1566.003 - Spearphishing via Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る