Skip to content

Coper

Coper is an Android banking trojan descended from the Exobot/ExobotCompact lineage and is also widely associated with the Octo name in later reporting.

Profile source: Mallory opens in a new tab

Coper

Family profile

Coper is an Android banking trojan descended from the Exobot/ExobotCompact lineage and is also widely associated with the Octo name in later reporting. First observed in 2021 targeting Colombian Android users, it evolved into a modular, multi-stage malware family used against banking customers in Europe, Turkey, Australia, parts of South America, and other regions. It is commonly distributed through trojanized Android applications that impersonate banking, security, utility, browser, or Google Play-related apps, including campaigns involving official app marketplaces, fraudulent landing pages, and SMS-based lures.

Coper typically begins as a dropper or loader application that requests extensive permissions and then decrypts and loads additional malicious code at runtime, often through native libraries and encrypted DEX payloads. It heavily abuses Android Accessibility Services to automate user-interface interaction, grant itself privileges, harvest on-screen content, and enable remote fraud. Observed variants also use Device Administration, notification access, SMS permissions, and background execution features to resist removal and maintain control of the device.

Its core functionality centers on banking fraud and credential theft. Capabilities documented across variants include overlay and webinject-based credential harvesting against banking applications, keylogging, interception of SMS messages and push notifications, theft of one-time passwords, collection of installed-app inventories and device metadata, and suppression of notifications to hide malicious activity. More advanced builds support VNC-like remote control or on-device fraud workflows, allowing operators to view screen contents, simulate taps and gestures, launch apps or URLs, lock the device, uninstall applications, and interact with targeted banking sessions in real time.

Coper employs multiple defensive and anti-analysis measures. These include encrypted strings and payloads, encrypted command-and-control traffic, integrity checks, restoration of removed components, repeated prompting for sensitive permissions, hiding launcher icons, monitoring attempts to revoke Accessibility or administrator privileges, and checks for emulators or other analysis environments in some variants. Several analyses also describe server-side victim filtering and geofencing behavior.

The malware has been linked to malware-as-a-service activity, with reporting indicating builder and panel infrastructure and possible overlap with operators active in Turkey. Campaigns have repeatedly targeted financial institutions and their customers, with especially notable activity reported in Turkey. Coper remains one of the more prominent Android banking trojans due to its combination of credential theft, SMS interception, remote device control, persistence, and anti-removal tradecraft.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Session Hijacking
  • Spoofing

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Aug 29, 2026
Feed role
C2
Host form
0 IP / 21 hostnames

Samples

Recent associated samples

MITRE ATT&CK

Coper in ATT&CK

38 distinct techniques

Reporting

Research mentioning Coper

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.