Investigation Report: Android/BankBot-YNRK Mobile Banking Trojan

Oct. 31, 2025, 10:51 a.m.

Description

This report analyzes three Android APK samples identified as variants of the Android/BankBot-YNRK malware family. The malware exhibits sophisticated capabilities, including environment detection, persistence mechanisms, and extensive command-and-control functionalities. It abuses accessibility services to gain elevated privileges, automates UI interactions, and extracts sensitive data. The trojan can masquerade as legitimate apps, suppress audio notifications, and perform unauthorized operations on infected devices. It targets financial applications and cryptocurrency wallets, enabling credential theft and fraudulent transactions. The malware communicates with a C2 server, exchanging device information and receiving commands for remote control. Overall, Android/BankBot-YNRK represents a significant threat to Android users, particularly those using banking and cryptocurrency applications.

Date

  • Created: Oct. 31, 2025, 9:30 a.m.
  • Published: Oct. 31, 2025, 9:30 a.m.
  • Modified: Oct. 31, 2025, 10:51 a.m.

Indicators

  • cb25b1664a856f0c3e71a318f3e35eef8b331e047acaf8c53320439c3c23ef7c
  • a4126a8863d4ff43f4178119336fa25c0c092d56c46c633dc73e7fc00b4d0a07
  • 19456fbe07ae3d5dc4a493bac27921b02fc75eaa02009a27ab1c6f52d0627423
  • plp.foundzd.vip
  • plp.en1inei2.top
  • plp.e1in2.top
  • ping.ynrkone.top

Attack Patterns

  • Android/BankBot-YNRK

Additional Informations

  • Finance