Exobot

MITRE ATT&CK: S0522 View on attack.mitre.org

Aliases: Exobot

First seen
2016-01-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
android
Related IoCs
37 (37 malicious)
Last IoC activity
2026-09-01 20:34:17
Profile updated
2026-07-07 14:05:20

Targeted industries: financial-services

Targeted regions: country_code:de country_code:at country_code:fr

Context

Exobot is Android banking malware, primarily targeting financial institutions in Germany, Austria, and France.

Recent IoC activity

37 malicious indicators in Maltiverse are attributed to Exobot (S0522). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname s22231232fdnsjds.top 2026-09-03 2
hostname utabwbazuu.com 2026-09-03 1
hostname sarahtame.at 2026-09-02 1
hostname thhausgajk.com 2026-09-02 1
hostname servercheck.online 2026-09-02 1
hostname loupeacara.net 2026-09-02 1
file sample BAWAG_PSK.apk 2026-08-16 2
hostname track-google.at 2026-08-16 1
hostname fastcheckdns.shop 2026-08-16 1
hostname barberink.biz 2026-08-12 1
hostname checks.design 2026-08-09 1
hostname xipxesip.club 2026-08-08 1
hostname s222231232fdnsjds.top 2026-08-02 1
hostname esappguide.com 2026-08-02 1
hostname checkdnsplus.space 2026-07-29 1
hostname i-app4.online 2026-07-22 1
hostname i-app5.online 2026-07-22 1
hostname wqetwertwertwerxcvbxcv.at 2026-07-19 1
hostname fastcheckdns.xyz 2026-07-18 1
hostname checkdns.digital 2026-07-12 1

Malware & tools used

  • Broadcast Receivers (attack-pattern)
  • SMS Control (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Web Protocols (attack-pattern)
  • SMS Messages (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Endpoint Denial of Service (attack-pattern)
  • Contact List (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Device Administrator Permissions (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Proxy Through Victim (attack-pattern)

Reports & references

  • blog.cyble.com — Coper Banking Trojan (report)
  • threatfabric.com — Octo New Odf Banking Trojan (report)
  • bleepingcomputer.com — New Android Banking Malware Remotely Takes Control Of Your Device (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Exobot (report)
  • bleepingcomputer.com — Exobot Author Calls It Quits And Sells Off Banking Trojan Source Code (report)
  • bleepingcomputer.com — Source Code For Exobot Android Banking Trojan Leaked Online (report)
  • bleepingcomputer.com — New Exo Android Trojan Sold On Hacking Forums Dark Web (report)
  • securityintelligence.com — Ibm X Force Delves Into Exobots Leaked Source Code (report)
  • MITRE ATT&CK — S0522 (report)
  • threatfabric.com — Exobot Android Banking Trojan On The Rise (report)

External references