Blog

The Rise of Banking Trojan Dropper in Google Play

The rise of banking Trojan Dropper in Google Play has become a reality, as the cyber crooks are using this malware to steal credit cards and bank accounts of unsuspecting victims. Currently, the malware is present in the form of TeaBot, SharkBot, Octo and DawDropper. These are some of the most prominent banking Trojans that […]
PX
Propelex team February 25, 2023 - 4 minutes read

The rise of banking Trojan Dropper in Google Play has become a reality, as the cyber crooks are using this malware to steal credit cards and bank accounts of unsuspecting victims. Currently, the malware is present in the form of TeaBot, SharkBot, Octo and DawDropper. These are some of the most prominent banking Trojans that have released recently, and it is only a matter of time until the other bots emerge as well.

SharkBot

The SharkBot banking Trojan is a relatively new Android banking trojan. First spotted in the wild back in October 2021, it initially targeted at European banks and crypto service customers. It uses a variety of tactics to get its hands on bank account credentials, allowing it to perform monetary transactions without a user’s authorization.

The malware aims to steal credentials through text messages and intercepted accessibility events. It also uses an External ATS module and string obfuscation to disguise itself as a legitimate app. The SharkBot also has some keylogging features and can launch electronic money transfers without a user’s authorization.

In addition, the malware’s cookie logger can be used to steal login cookies. It can also use a geofencing feature to identify potential victims.

Vultur

The Vultur banking trojan has reached over 100,000 downloads on Google Play. Its unique features have drawn the attention of malware researchers. It aims to steal financial data and bank details from users. It also records online activity and logs keystrokes from targeted applications. The malware relies on AES encryption to obfuscate its malicious nature.

This new variant of the banking Trojan distributed through a network of droppers. These droppers are posing as utility apps on Google Play. But a deeper look at the droppers reveals that they are all designed to install the same piece of malware.

The dropper’s functionality derived from a combination of steganography, code obfuscation, and advanced detection evasion. It’s designed to reach more potential victims by bypassing detection systems.

DawDropper

Security researchers at Trend Micro recently uncovered a malicious campaign based on Android dropper apps on Google Play. The campaign disguised itself as productivity and document scanners, and used Android dropper apps to deliver four banking trojans to targeted Android devices.

The droppers designed to bypass the security analysis of the Google Play Store, which allows them to get through to an unsuspecting user. This allows cybercriminals to infect as many devices as possible. The best way to avoid falling for the scam is to download applications only from the official Google Play store. However, it is also important to check reviews for any new apps you are considering downloading.

A recent report from Threat Fabric reveals the rise of banking trojan in Google Play by using “Dropper”. The dropper-as-a-service approach enables digital miscreants to reach a broader audience while still maintaining a low price and high quality.

Octo

Several versions of the BankBot mobile banking trojan still distributed on the Google Play Store until November 17th. However, Google has now removed them from the store. It is important to keep an eye on this malware.

The BankBot Trojan has been circulating in the wild for months, but the authors of the malware are finding new ways to get around detection. One such technique involves using dropper apps to distribute their banking trojans.

This method of distributing the malware works by hiding the real app behind a convincing overlay. The attacker can then obtain login and credit card details via the fake app. Once the fake overlay downloaded, the real banking app will replace with the overlay, which will request a combination of login and credit card information.

TeaBot

TeaBot, a banking trojan that can steal sensitive information and financial data, has made its way into the Google Play Store. In a report released by Clefy, a risk management firm, it found that the Android malware was spreading and gaining traction.

The trojan typically comes packaged in a dropper application. It aims to intercept SMS messages, login credentials, and crypto wallets. It also works as a remote access tool, which allows it to control a user’s device.

TeaBot’s latest incarnation consists of a QR code reader app. It’s downloaded over 10,000 times and distributed 17 variants of the malware. This means that it’s not just a new Android malware – it’s a new form of the banking trojan.

Work with Propelex

Ready to build AI
into your stack?

Propelex helps teams evaluate, integrate, and scale AI workflows — from MCP strategy to full agentic architecture. Let's find the right entry point for your organization.