Categories: EducationFAQMalware

What is BankBot?

Android users may have noticed how there is a sudden surge in banking malware on the platform all of a sudden. In fact, these problems date back to December of 2016. It turns out the surge of BankBot malware can all be attributed to one person posting a tutorial on how to build Android malware. It is evident criminals want to share their expertise, which does not bode well for the rest of the world.

What on Earth is BankBot Malware?

It is quite interesting to see how one person is responsible for a lot of banking malware issues affecting Android users around the world. As it turns out, the tutorial to build Android malware dates back to December 2016. It is also a very easy tutorial, which takes interested parties by the hand, and explains everything one needs to know in detail. With this guide, anyone in the world is more than capable of creating a basic Android banking Trojan. It turns out this was all made possible thanks to BankBot.

More specifically, one can put BankBot on the same level as other major banking Trojans, such as ZeuS and EDA2. However, BankBot was a unique type of banking malware, which also served as the basis for a lot of future creations making use of the same features. BankBot is capable of communicating with a web-based backend, which is a rather common feat in the world of malware these days.

Once the BankBot tutorial was released on a well-known hacking forum, it only took about a month until different versions of it started popping up. In the first wave of attacks, the malware mainly targeted Russian banks. This was considered quite a troublesome development, as no malware has been capable of infiltrating those banks. Interestingly enough, this first version was not distributed through the Google Play Store, but mainly focused on third-party APK download sites. Luckily, these campaigns were detected and shut down relatively quickly.

Related Post

One would expect such a big setback to spell the end of BankBot, but that is not the case by any means. Instead, the past three months have seen a new surge of activity where this malware is concerned. The tutorial on creating Android banking malware has made its way to other forums frequented by cybercriminals as of late. So far, there have been 62 different BankBot campaigns, with most of them taking place over the past three months.

What is even more troublesome is how the BankBot banking Trojan successfully evades security checks implemented by the Google Play Store. A lot of the current distribution campaigns originate from the applications listed in the Google Play Store. That is very disturbing, to say the least. It turns out the malware developers are getting better at obfuscating the malware’s code. Google’s automatic malware scanners are incapable of detecting BankBot right now, although that situation may be resolved sooner rather than later.

It is evident BankBot is causing a lot of headaches among Android users around the world. Android malware is a very big problem, Current iterations of BankBot can display overlays on top of applications, intercept text messages, and even steal credentials from applications. Considering how the original tutorial can still be found on the darknet, it is not unlikely we will see more BankBot campaigns over the coming months.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Velocity Ticket Debuts As The AI-Powered Invoicing Tool Every Service Business Needs in 2026

Velocity Ticket is trying to fix a major gap in businesses, and the approach it…

2 days ago

Axelar Confirms $4.67M Exploit on Secret Network Bridge, Core Protocol Remains Unaffected

Axelar is moving fast to contain damage after identifying a security incident that has resulted…

3 days ago

Sui Synthetic Dollar suiUSDe Gets Its Own Website

suiUSDe now has a dedicated landing page. The token, officially the eSui Dollar, comes out…

3 days ago

Ventuals Winds Down HIP-3 DEX, vHYPE Withdrawals Now Live For All Holders

Ventuals has fully wound down its HIP-3 DEX, and vHYPE withdrawals are now open. The…

3 days ago

Avalanche Launches Payments Collective With Franklin Templeton And 25 Others

Avalanche has launched the Avalanche Payments Collective, bringing together 28 organizations spanning nearly every layer…

4 days ago

ASTER Whale Reopens 5x Long Days After Getting Fully Liquidated On The Same Token

A wallet tracked as 0x5f91 just opened a fresh 5x leveraged long on ASTER, putting…

4 days ago