Exobot
MITRE ATT&CK: S0522 View on attack.mitre.org
Aliases: Exobot
- First seen
- 2016-01-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 37 (37 malicious)
- Last IoC activity
- 2026-09-01 20:34:17
- Profile updated
- 2026-07-07 14:05:20
Targeted industries: financial-services
Targeted regions: country_code:de country_code:at country_code:fr
Context
Exobot is Android banking malware, primarily targeting financial institutions in Germany, Austria, and France.
Recent IoC activity
37 malicious indicators in Maltiverse are attributed to Exobot (S0522). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | s22231232fdnsjds.top | 2026-09-03 | 2 |
| hostname | utabwbazuu.com | 2026-09-03 | 1 |
| hostname | sarahtame.at | 2026-09-02 | 1 |
| hostname | thhausgajk.com | 2026-09-02 | 1 |
| hostname | servercheck.online | 2026-09-02 | 1 |
| hostname | loupeacara.net | 2026-09-02 | 1 |
| file sample | BAWAG_PSK.apk | 2026-08-16 | 2 |
| hostname | track-google.at | 2026-08-16 | 1 |
| hostname | fastcheckdns.shop | 2026-08-16 | 1 |
| hostname | barberink.biz | 2026-08-12 | 1 |
| hostname | checks.design | 2026-08-09 | 1 |
| hostname | xipxesip.club | 2026-08-08 | 1 |
| hostname | s222231232fdnsjds.top | 2026-08-02 | 1 |
| hostname | esappguide.com | 2026-08-02 | 1 |
| hostname | checkdnsplus.space | 2026-07-29 | 1 |
| hostname | i-app4.online | 2026-07-22 | 1 |
| hostname | i-app5.online | 2026-07-22 | 1 |
| hostname | wqetwertwertwerxcvbxcv.at | 2026-07-19 | 1 |
| hostname | fastcheckdns.xyz | 2026-07-18 | 1 |
| hostname | checkdns.digital | 2026-07-12 | 1 |
Malware & tools used
- Broadcast Receivers (attack-pattern)
- SMS Control (attack-pattern)
- Security Software Discovery (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Web Protocols (attack-pattern)
- SMS Messages (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Keylogging (attack-pattern)
- Endpoint Denial of Service (attack-pattern)
- Contact List (attack-pattern)
- GUI Input Capture (attack-pattern)
- Device Administrator Permissions (attack-pattern)
- System Information Discovery (attack-pattern)
- Proxy Through Victim (attack-pattern)
Reports & references
- blog.cyble.com — Coper Banking Trojan (report)
- threatfabric.com — Octo New Odf Banking Trojan (report)
- bleepingcomputer.com — New Android Banking Malware Remotely Takes Control Of Your Device (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Exobot (report)
- bleepingcomputer.com — Exobot Author Calls It Quits And Sells Off Banking Trojan Source Code (report)
- bleepingcomputer.com — Source Code For Exobot Android Banking Trojan Leaked Online (report)
- bleepingcomputer.com — New Exo Android Trojan Sold On Hacking Forums Dark Web (report)
- securityintelligence.com — Ibm X Force Delves Into Exobots Leaked Source Code (report)
- MITRE ATT&CK — S0522 (report)
- threatfabric.com — Exobot Android Banking Trojan On The Rise (report)