216.73.216.6

DroidBot: Insights from a new Turkish MaaS fraud operation

· Published 09/12/2024 22:22 · Modified 09/12/2024 22:32

Export JSON

Essential information

Published
09/12/2024 22:22
Modified
09/12/2024 22:32
Tags
2024-12-09 android banking trojan droidbot
Related entities
5 observables, 3 techniques (mitre), 1 malware, 8 others

Description

is an advanced Remote Access Trojan combining hidden VNC and overlay capabilities with spyware features. It uses dual-channel communication, transmitting data via MQTT and receiving commands through HTTPS. The malware targets 77 entities, including banks and cryptocurrency exchanges, in countries like the UK, Italy, France, Spain, and Portugal. Evidence suggests Turkish-speaking developers and a Malware-as-a-Service operation with 17 distinct affiliate groups. is under active development, showing inconsistencies across samples. Its sophisticated features, diverse target list, and MaaS infrastructure make it a significant threat to financial institutions and government entities across multiple regions.

External references