BlankBot: A new Android banking trojan

Aug. 6, 2024, 10:35 a.m.

Description

A new Android banking trojan called BlankBot has been discovered. Discovered by Intel 471 researchers in July 2024, BlankBot primarily targets Turkish users through impersonated utility apps. With a range of malicious capabilities like customer injections, keylogging, screen recording, and remote control via WebSocket connection to a command server, BlankBot can steal sensitive data. Most samples remain undetected by antivirus software at the time of discovery. The malware appears to still be under development with code variants and logs present.

Date

Published: Aug. 6, 2024, 10:04 a.m.

Created: Aug. 6, 2024, 10:04 a.m.

Modified: Aug. 6, 2024, 10:35 a.m.

Attack Patterns

BlankBot