Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2
- Host form
- 0 IP / 5 hostnames
SharkBot is an Android banking trojan and stealer first identified in late 2021.
Profile source: Mallory opens in a new tabSharkBot
SharkBot is an Android banking trojan and stealer first identified in late 2021. It is designed primarily for financial fraud and account takeover against mobile banking users, with campaigns notably targeting users in Italy and the United Kingdom before expanding to additional countries. The malware has commonly been distributed through malicious Android applications masquerading as antivirus, cleaner, tax, or file-management tools, including apps uploaded to Google Play, and later installs or updates the full payload on victim devices.
A defining characteristic of SharkBot is its aggressive abuse of Android Accessibility Services. After installation it persistently seeks accessibility privileges, uses them to automate permission grants, monitor foreground applications and user-interface events, capture text input, and interact with banking apps on the victim’s behalf. SharkBot supports overlay-based credential theft, keylogging via accessibility event capture, interception and concealment of SMS messages, SMS sending, contact theft, and exfiltration of captured credentials and event logs to command-and-control infrastructure over HTTP. It can also hide its launcher icon, request exemption from battery optimizations to maintain connectivity, interfere with uninstall attempts, and in some variants change the device’s default SMS handler.
Later SharkBot versions expanded beyond basic overlay fraud. Version 2.x introduced a refactored communication scheme and an evolving fallback domain generation algorithm for resilient command-and-control, an uncommon feature in Android malware. SharkBot also supports downloading additional modules and executing remote commands to open applications, uninstall selected apps, block access to targeted apps, and emulate user gestures. More advanced variants added Automatic Transfer System functionality to automate fraudulent transactions inside legitimate banking applications, and version 2.25 introduced session-cookie theft by loading attacker-controlled web content in a WebView and extracting banking session cookies after victim login.
SharkBot has shown anti-analysis and anti-emulation behavior, geofencing in some campaigns, and steady iterative development across multiple versions. Early reporting assessed it as a privately operated malware family rather than a broadly marketed commodity tool. Its combination of accessibility abuse, SMS interception, credential theft, ATS-driven fraud, and resilient command-and-control makes it one of the more capable Android banking trojans observed in the 2021-2022 period.
C2 tracking
Derp observations, rolling seven-day window
Samples
25e2a148a586acc6b741a64f42c618796a08ec9745eb3d1170acabf9e732a366 618ee1e79a927c57831527faf19739276f2706b6200ee8f52aa0eb0c66de6828 900fe34d5394689c86ead76666e79620ad7a10109c75d661af9bc7d8fb0c27b8 b45edcbdfe9ad1a1990d723dca4405014a4fa1c578b75799219a4298b16175de fa7947933a3561b7174f1d94472dcf8633a03749c14342ce65dafe94db361140 a56dacc093823dc1d266d68ddfba04b2265e613dcc4b69f350873b485b9e1f1c b4a031c10801de4e89d7d66f26824d9066c4c217c06386dc102a08c26a81d4f0 d05fb8c6899c96d1519e46eaea848ead6a17c7ddd0e20228e83c1aa9f264011d dd0641f261d75864b164a7f963b45dc43c6c815ad01e5f51c29504c668e6d5ec e5b96e80935ca83bbe895f6239eabca1337dc575a066bb6ae2b56faacd29ddaa MITRE ATT&CK
Reporting
Researchers identified an Android malware app named iMobile that impersonates India’s Income Tax Department and targets Indian taxpayers through phishing, harvesting sensitive data including PAN, Aadhaar, bank account information, debit card details, and internet banking credentials. The app also seeks extensive dangerous permissions and attempts to set itself as the device’s default SMS application, giving it the ability to read, receive, and send text messages while monitoring phone state and usage data. Analysis showed the stolen banking and internet-banking information was uploaded to the command-and-control endpoint jsig.quicksytes[.]com/MC/NN180521/mc.php, and the sample used string deobfuscation and hardcoded artifacts including an Indian mobile number. The campaign reflects a broader mobile threat pattern documented in MITRE ATT&CK T1636.004, where malicious apps abuse SMS access to intercept messages, including one-time passcodes and transaction alerts, to support credential theft, financial fraud, and account takeover.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.