Skip to content

SharkBot

SharkBot is an Android banking trojan and stealer first identified in late 2021.

Profile source: Mallory opens in a new tab

SharkBot

Family profile

SharkBot is an Android banking trojan and stealer first identified in late 2021. It is designed primarily for financial fraud and account takeover against mobile banking users, with campaigns notably targeting users in Italy and the United Kingdom before expanding to additional countries. The malware has commonly been distributed through malicious Android applications masquerading as antivirus, cleaner, tax, or file-management tools, including apps uploaded to Google Play, and later installs or updates the full payload on victim devices.

A defining characteristic of SharkBot is its aggressive abuse of Android Accessibility Services. After installation it persistently seeks accessibility privileges, uses them to automate permission grants, monitor foreground applications and user-interface events, capture text input, and interact with banking apps on the victim’s behalf. SharkBot supports overlay-based credential theft, keylogging via accessibility event capture, interception and concealment of SMS messages, SMS sending, contact theft, and exfiltration of captured credentials and event logs to command-and-control infrastructure over HTTP. It can also hide its launcher icon, request exemption from battery optimizations to maintain connectivity, interfere with uninstall attempts, and in some variants change the device’s default SMS handler.

Later SharkBot versions expanded beyond basic overlay fraud. Version 2.x introduced a refactored communication scheme and an evolving fallback domain generation algorithm for resilient command-and-control, an uncommon feature in Android malware. SharkBot also supports downloading additional modules and executing remote commands to open applications, uninstall selected apps, block access to targeted apps, and emulate user gestures. More advanced variants added Automatic Transfer System functionality to automate fraudulent transactions inside legitimate banking applications, and version 2.25 introduced session-cookie theft by loading attacker-controlled web content in a WebView and extracting banking session cookies after victim login.

SharkBot has shown anti-analysis and anti-emulation behavior, geofencing in some campaigns, and steady iterative development across multiple versions. Early reporting assessed it as a privately operated malware family rather than a broadly marketed commodity tool. Its combination of accessibility abuse, SMS interception, credential theft, ATS-driven fraud, and resilient command-and-control makes it one of the more capable Android banking trojans observed in the 2021-2022 period.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Aug 29, 2026
Feed role
C2
Host form
0 IP / 5 hostnames

Leading locations

  • US1

Leading providers

  • Google LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

SharkBot in ATT&CK

23 distinct techniques

Reporting

Research mentioning SharkBot

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.