Android malware analysis & C2 intelligence
We detonate real Android samples on a de-emulated Android 17 device that malware can't fingerprint as virtual, then recover their command-and-control indicators. These are honest, evidence-based write-ups — with the environmental noise removed and the limits stated.
Hook
Hook is an Android banking trojan and remote-access tool, derived from the ERMAC codebase and sold as malware-as-a-service, that combines overlay credential theft with real-time device takeover through VNC-style remote control abusing the accessibility service.
3 C2 indicator(s) · analyzed 2026-09-14 Android banking trojanERMAC
ERMAC is an Android banking trojan derived from the leaked Cerberus code base that uses overlay attacks and keylogging to steal credentials from hundreds of banking, cryptocurrency, and shopping apps.
1 C2 indicator(s) · analyzed 2026-09-08 Android banking trojanTrickMo
TrickMo is an Android banking trojan linked to the TrickBot cybercrime gang that abuses Android accessibility services to intercept one-time passwords, record and stream the screen, phish credentials with overlays, and steal device unlock PINs and patterns for on-device fraud.
1 C2 indicator(s) · analyzed 2026-09-08 Android banking trojanGodfather
Godfather is an Android banking trojan, derived from the leaked Anubis source code and sold as malware-as-a-service, that steals credentials and commits on-device fraud against a very large global list of banking and cryptocurrency apps.
2 C2 indicator(s) · analyzed 2026-09-08 Android remote access trojan (RAT) / banking trojan used for on-device fraudBingoMod
BingoMod is an Android remote access trojan, first documented by Cleafy in 2024, that abuses Accessibility Services to perform live-operator on-device fraud (account takeover money transfers) and then typically wipes the infected device to hinder forensic analysis.
2 C2 indicator(s) · analyzed 2026-09-08 Android credential- and 2FA-stealing malware (fake-app phishing family)Fluhorse
Fluhorse is an Android malware family, first documented by Check Point Research in May 2023, that ships as fake versions of legitimate East Asian apps to steal login credentials, payment-card data, and SMS-delivered 2FA codes.
1 C2 indicator(s) · analyzed 2026-09-08 Android banking trojanSoumniBot
SoumniBot is an Android banking trojan targeting South Korean users that evades static analysis by corrupting its AndroidManifest.xml and steals online-banking credentials, SMS, and Korean digital banking certificates while taking commands over MQTT.
2 C2 indicator(s) · analyzed 2026-09-08 Android banking trojan / remote access trojan (offered as malware-as-a-service)Coper
Android banking trojan and remote access tool sold as malware-as-a-service; a descendant of the Exobot/ExobotCompact lineage that performs on-device fraud via credential overlays, keylogging, SMS and notification interception, and accessibility-driven remote control.
5 C2 indicator(s) · analyzed 2026-09-08 Android banking trojan (offered as malware-as-a-service)Cerberus
Cerberus is an Android banking trojan sold as a malware-as-a-service that abuses accessibility services and overlay attacks to steal banking credentials, intercept SMS, and bypass two-factor authentication; its source code was released publicly in 2020 and became the basis for later families such as Alien and ERMAC.
1 C2 indicator(s) · analyzed 2026-09-08 Android banking trojan / SMS stealerMamont
An Android banking trojan and SMS stealer that targets Russian-speaking users, spread through Telegram and messenger phishing while posing as parcel-tracking, video, or brand-name apps, and used to intercept SMS and notifications and drain accounts through SMS banking.
1 C2 indicator(s) · analyzed 2026-09-08 Android banking trojan (device-takeover banker with RAT/spyware capabilities)Brokewell
A device-takeover Android banking trojan that abuses the Accessibility service to log input, overlay banking apps, stream the screen, and give operators full remote control of infected devices.
1 C2 indicator(s) · analyzed 2026-09-08How these were produced
Each sample was obtained from MalwareBazaar (abuse.ch) and detonated in an isolated, per-sample environment on Privara Unmask. Because the device is de-emulated, samples that normally stay dormant under analysis behaved as they would on a real handset, exposing their configuration and C2. We publish a C2 only when the evidence supports it, distinguish a recovered identity from a live beacon, and remove shared/benign infrastructure (CDN fronting, messaging transport, analytics) instead of inflating the indicator count.
Put your own samples under Privara Unmask
Automated detonation, unpacking and C2 recovery on a device anti-analysis code can't fingerprint — with clean rollback per sample.
See the sandbox → Request a demo