Skip to content
Malware family

SharkBot

SharkBot is an Android banking malware family first reported by the Cleafy Threat Intelligence Team at the end of October 2021.

Profile source: Mallory opens in a new tab

SharkBot

Family profile

SharkBot is an Android banking malware family first reported by the Cleafy Threat Intelligence Team at the end of October 2021. It steals banking credentials and banking details and is described as one of the notable mobile banking malware families active in 2022. The malware targets Android devices and performs overlay attacks against targeted applications, especially banking and cryptocurrency apps. It abuses Android Accessibility Services to control the device, interact with app interfaces, auto-fill fields, simulate clicks and gestures, and support Automatic Transfer System (ATS) fraud to initiate unauthorized money transfers.

Documented capabilities include intercepting, hiding, collecting, and exfiltrating SMS messages; stealing contacts; keylogging victim keystrokes; stealing cookies; and exfiltrating captured user credentials and event logs to command-and-control infrastructure. SharkBot can hide and send SMS messages, change the device’s default SMS handler, and on some Android versions request or abuse SMS-related permissions, including becoming the default SMS app. Older samples implemented an Auto Direct Reply feature that replied to intercepted message notifications with malicious links used to spread a SharkBot dropper or APK, while newer versions reportedly removed that feature.

For command and control, SharkBot uses HTTP, including HTTP POST requests to send device status and permission information, and can receive commands such as stopAll, openPackage, removeApp, getDoze, ats, enableKeyLogger, and sendSMS. In addition to hard-coded infrastructure, SharkBot uses a fallback domain generation algorithm (DGA), which is noted as unusual for Android malware. Multiple DGA versions are described: 0.0.0, 1.63.3, 2.1, and 2.8. Earlier variants used Base64-derived domains based on the current week and a hardcoded string; later variants switched to MD5-derived generation using the current week, current year, and TLDs including .xyz, .live, .com, .store, .info, .top, and .net. Version 2.8 corrected a flaw present in 2.1 so generated domains differ across years.

Persistence and evasion behaviors include requesting Accessibility permissions, hiding the app icon, disrupting uninstall attempts by returning the user to the home screen, and anti-emulator checks that prevent launch or C2 communication when an emulator is detected.

High-confidence indicators mentioned in the content include package names com.btfezxwhygk2dw0gaj.eguafyojiqcw7a and com.ohalqpdj.discopet; hard-coded C2 URL http://f3eac8de096e59ca.live/; sample hashes 0356f17f28778da7c97dc8b661c0aeb0 / 2c4828f926471ec4f3522fc28dd4d8fdec692c35 / 76b4ee2da4e39677038ea033f25652fb02ed9e84ab829ce212fa1dfbc941df2c for version 0.0.0, 48ad4e0478e4d742f51848604d06130e / a9ca49ef2201707b7bcf57798fc67e69d238c900 / c14f413d8ed944ba7e4364e6b17585019fd622feeb4b53f7002a742d7389e08a for version 1.63.3, 92011ba743860567b85f46aedf360661 / 506df2fd2e638ab614eeb4cbc416bd46fdbf6a19 / 70b244a03a0eacd00cc52ea8863af2c459eb8dc2e6bf5887e657b401e0477485 for version 2.1, 2dfe83d4d7c0b5e0cfc0537efdbbbb01 / f1a820369f02a696e8bcaecee464eeaef0847c44 / dae193b7cac6d048dcc37916c92b0d2b11c56aa3f45e9995c16417e3b0587404 for version 2.8, and SHA256 hashes d05fb8c6899c96d1519e46eaea848ead6a17c7ddd0e20228e83c1aa9f264011d for an older sample and bf3fcdba7148627abfed402d038c99d3b2e60cd87cd04fe22b6ea3aac5ac9151 for a SharkBot v2.6 sample.

Observed infrastructure

Last seven days

First activity
Jul 20, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

MITRE ATT&CK

SharkBot in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.