Drinik

MITRE ATT&CK: S1054 View on attack.mitre.org

Aliases: Drinik

First seen
2016-01-01 00:00:00
Malware type
trojan, credential-stealer, spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:30:21

Targeted industries: financial-services

Targeted regions: country_code:in

Context

Drinik is an evolving Android banking trojan that was observed targeting customers of around 27 banks in India in August 2021. Initially seen as an SMS stealer in 2016, Drinik resurfaced as a banking trojan with more advanced capabilities included in subsequent versions between September 2021 and August 2022.

Malware & tools used

  • SMS Control (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Call Control (attack-pattern)
  • Keylogging (attack-pattern)
  • Screen Capture (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Foreground Persistence (attack-pattern)
  • Call Log (attack-pattern)
  • SMS Messages (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Data from Local System (attack-pattern)
  • Application Layer Protocol (attack-pattern)
  • Suppress Application Icon (attack-pattern)

Reports & references

  • MITRE ATT&CK — S1054 (report)
  • web.archive.org — Drinik Malware Returns With Advanced Capabilities Targeting Indian Taxpayers (report)

External references