International Cyber Expo International Cyber Expo
  • About Us
Wednesday, 22 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

New MaliBot Android Banking Malware Poses as Cryptocurrency Mining App

The malware is targeting mobile banking users in Spain and Italy.

by Guru Writer
June 17, 2022
in Cyber Bites
Smartphone
Share on FacebookShare on Twitter

A new Android banking malware named MaliBot has been discovered by cybersecurity researchers. The malware poses as a cryptocurrency mining app or the Chrome web browser to target users in Spain and Italy.

MaliBot focuses on stealing financial information, like e-banking credentials, crypto wallet passwords, and sensitive personal details. It is also capable of snatching two-factor authentication codes from notifications.

The malware was discovered by analysts at F5 Labs, who wrote a report with their findings. The report noted that the new malware is currently using multiple distribution channels, likely aiming to cover the gap in the market created by the shutdown of the FluBot operation.

MaliBot’s command and control server is based in Russia. Its IP has been associated with several malware distribution campaigns since June 2020.

The distribution of the malware takes place via websites that promote cryptocurrency applications in the form of APKs that victims download and install manually.

The sites pushing these files are clones of real projects like TheCryptoApp, which already has over a million downloads on the Google Play Store.

In another campaign, the malware is published as an app called Mining X. In this campaign victims are tricked into scanning a QR code to download the malicious APK file.

MailBot operators also use SMS phishing (smishing) messages to distribute their payloads to a list of telephone numbers determined by the C2. These messages are distributed by a compromise device abusing the “send SMS” permission.

The malware is a powerful trojan that secures accessibility and launcher permissions upon installation and then grants itself additional rights on the device.

MaliBot can intercept notifications, calls, SMS, capture screenshots, register boot activities, and give its operators remote control capabilities via a VNC system.

VNC allows the operations to navigate between screens, scroll, take screenshots, copy content, perform long presses, etc.

To evade MFA protections, it abuses the Accessibility API to click on confirmation prompts regarding suspicious login attempts, sends the OTP to the C2, and fills it out automatically.

Additionally, the malware can steal MFA codes from Google Authenticator and perform this action on-demand.

MaliBot retrieves a list of installed apps to determine which banks are used by the victim to fetch the matching overlays/injections from the C2.

The analysts have seen unimplemented features in the code of MaliBot, like the detection of emulated environments that could be used to evade analysis.

This shows that the development is active. New versions of the MaliBot are expected to enter circulation soon.

At present, MaliBot loads overlays that target Italian and Spanish banks. There are fears that it could expand by adding more injections.

ShareTweet
Previous Post

Several Data-Stealing Apps Remain on Google Play Store According to Cybersecurity Researchers

Next Post

Chinese Hackers Exploited Critical Security Vulnerability in Sophos Firewall

Recent News

privileged access management

KeeperPAM strengthens privileged access management for global construction SaaS provider Asite

July 21, 2026
Forescout 2026 H1 Threat Review

Forescout Report Reveals Surge in AI-Driven Cyber Threats

July 21, 2026
secure-software-supply-chain-feature

1 in 4 businesses hit by cyber attacks through their supply chain in the last year

July 21, 2026
partnership

DigiCert expands its EMEA channel strategy with Ignition Technology

July 21, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol