Zimperium, notable for AI-based mobile security, has disclosed new findings from its zLabs threat research team, identifying four active Android banking trojan campaigns known as RecruitRat, SaferRat, Astrinox, and Massiv. Collectively, these trojans are targeting over 800 applications across the banking, cryptocurrency, and social media sectors worldwide.
The research underscores how these malware families have grown beyond simple credential theft, now employing advanced phishing strategies, deceptive overlays, Accessibility abuse, screen capture, and anti-analysis methods to avoid detection, facilitating account takeovers and financial crimes.
Enhanced anti-analysis techniques
The study reveals that these campaigns utilise sophisticated command-and-control (C2) frameworks alongside multi-stage infection processes to establish persistence on compromised devices. This enables them to intercept SMS-based one-time passwords, harvest device credentials, and exfiltrate sensitive information in real-time.
The research underscores how these malware families have grown beyond simple credential theft
zLabs discovered that these malware families achieve near-zero detection rates against traditional mobile security solutions by using advanced techniques like APK tampering, encrypted payloads, dynamic code loading, and environment-aware execution. According to Krishna Vishnubhotla, VP of Product Strategy at Zimperium, “As cybercriminals adopt a mobile-first attack strategy, Android banking trojans are becoming more evasive and effective. These campaigns go beyond credential theft, taking over the device itself to bypass security controls and enable fraud—highlighting the need for dedicated mobile security.”
Unique infection chains
Key observations from zLabs include:
- Four distinct Android banking trojan families with unique infection chains and malware behaviours
- More than 800 applications in sectors such as banking, cryptocurrency, and social media being targeted
- Delivery methods including phishing websites, fraudulent job recruitment lures, deceptive streaming offers, and smishing campaigns
- Exploitation of Accessibility Services, MediaProjection, overlays, and Session Installation APIs to maintain persistence and avoid detection
- Functionalities like keylogging, screen capture, credential theft, SMS interception, device analysis, and phishing overlay injection
Exploitation of legitimate features
The research further highlights an increasing misuse of legitimate Android services
The research further highlights an increasing misuse of legitimate Android services and trusted user experiences to conceal malicious actions. In numerous instances, trojans disguised themselves as system updates, employment-related applications, or streaming services to deceive users into installing harmful APKs. Once activated, the malware can dynamically detect installed banking and crypto apps, deploy sophisticated phishing overlays, and capture critical information such as credentials, PINs, and one-time authentication codes.
For enterprises, this threat presents risks beyond consumer banking fraud. Compromised mobile devices in the hands of employees may allow attackers to intercept authentication processes, hijack sessions, and gain unauthorised access to sensitive corporate data, making mobile malware a significant concern for enterprise security.
Zimperium provides protection against these threats through its AI-driven, on-device mobile threat defence and runtime protection solutions. These capabilities can identify behavioural indicators, such as Accessibility exploitation, covert screen sharing, malicious sideloading, and phishing infrastructure, intercepting threats before they can spread.
