Coper
Also known as: ExobotCompact, Octo
Coper is an Android banking trojan and RAT descended from ExobotCompact, itself a rewrite of Exobot. It uses a modular architecture, a multi-stage infection chain and (in some variants) a DGA. First observed in Colombia, it has since spread to Europe.
Last 7 days
Apr 6, 2026
C2 Hosts: 10
| Date | C2 Hosts |
|---|---|
| Apr 6, 2026 | 10 |
Further Reading
Botnet C&C | Botnet Threat Update January to June 2025 | Report
spamhaus.org
Botnet C&C | Botnet Threat Update July to December 2025 | Report
spamhaus.org
Coper / Octo - A Conductor for Mobile Mayhem | Team Cymru
Explore Coper/Octo, an Android malware-as-a-service evolved from Exobot, targeting users globally with remote access, keylogging, and SMS interception. Contact us.
team-cymru.com
Octo2: European Banks Already Under Attack by New Malware Variant
ThreatFabric unveils the evolution of Octo2 malware, enhancing mobile banking security with sophisticated techniques and remote access capabilities.
threatfabric.com
Examining New DawDropper Banking Dropper and DaaS on the Dark Web
trendmicro.com
Virus Bulletin :: Octopus Prime: it didn't turn into a truck, but a widely spread Android botnet
VB2024 paper: Octopus Prime: it didn't turn into a truck, but a widely spread Android botnet, Thibault Seret
virusbulletin.com