SharkBot

MITRE ATT&CK: S1055 View on attack.mitre.org

Aliases: SharkBot

Malware type
trojan
Family
Malware family
Operating systems
android
Related IoCs
36 (27 malicious)
Last IoC activity
2026-09-01 16:16:25
Profile updated
2026-07-07 14:04:45

Targeted industries: financial-services

Context

SharkBot is a banking malware, first discovered in October 2021, that tries to initiate money transfers directly from compromised devices by abusing Accessibility Services.

Recent IoC activity

27 malicious indicators in Maltiverse are attributed to SharkBot (S1055). The 20 most recently updated:

TypeIndicatorUpdatedSources
IP address 176.10.125.87 2026-09-01 3
file sample b4c7d493dafb443a9e03a0f7634ba2a2_SharkBot_187b9f5de09d.apk 2026-08-26 2
file sample 25e2a148a586acc6b741a64f42c618796a08ec9745eb3d1170acabf9e732a366.apk 2026-08-22 2
file sample d05fb8c6899c96d1519e46eaea848ead6a17c7ddd0e20228e83c1aa9f264011d.apk 2026-08-21 2
file sample 618ee1e79a927c57831527faf19739276f2706b6200ee8f52aa0eb0c66de6828.apk 2026-08-20 1
file sample dd0641f261d75864b164a7f963b45dc43c6c815ad01e5f51c29504c668e6d5ec.apk 2026-08-20 2
file sample fa7947933a3561b7174f1d94472dcf8633a03749c14342ce65dafe94db361140.apk 2026-08-19 1
file sample b4a031c10801de4e89d7d66f26824d9066c4c217c06386dc102a08c26a81d4f0.apk 2026-08-18 1
file sample 8f9b45c674d016ac6d7d48556408206c8e20a292d555ad64143718504ad55e13.apk 2026-08-17 1
file sample 844efceeeeff73da35ac13c217ad5723c456ecec01fada7f92b9203fc29e7dcd.apk 2026-08-17 1
file sample 7f55dddcfad05403f71580ec2e5acafdc8c9555e72f724eb1f9e37bf09b8cc0c.apk 2026-08-17 1
file sample 72512e7de8099e66beb9b4395b8c4a5c1dfd413c85977a31480ff8bd68b2ca6e.apk 2026-08-17 1
file sample 71c78101f7792fe879a082e323fed89c5e4a43132d01d3f79ed02afd8db45497.apk 2026-08-17 1
file sample 6f1eb9c21b026eecfd65459ec4cffe3954d24619010741e18722108d7bacf3d1.apk 2026-08-17 1
IP address 185.219.221.65 2026-08-16 2
hostname mja1nxbvakjjouxir0z.com 2026-07-24 1
file sample Center+Security+-+Antivirus_1.1_APKPure.apk 2026-07-20 1
hostname admfor.me 2026-07-13 1
hostname 75b84d88067cb231.xyz 2026-07-09 1
hostname 5a8777db35d45d0a.live 2026-07-03 1

Malware & tools used

  • Download New Code at Runtime (attack-pattern)
  • Out of Band Data (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Process Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)
  • Uninstall Malicious Application (attack-pattern)
  • SMS Messages (attack-pattern)
  • Input Injection (attack-pattern)
  • Application Versioning (attack-pattern)
  • SMS Control (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Web Protocols (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Access Notifications (attack-pattern)

Reports & references

  • threatfabric.com — The Attack Of The Droppers (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Sharkbot (report)
  • bin.re — The Dgas Of Sharkbot (report)
  • cleafy.com — Sharkbot A New Generation Of Android Trojan Is Targeting Banks In Europe (report)
  • services.google.com — Gcat Threathorizons Full Jul2023 (report)
  • research.nccgroup.com — Sharkbot A New Generation Android Banking Trojan Being Distributed On Google Play Store (report)
  • muha2xmad.github.io — Sharkbot (report)
  • research.checkpoint.com — Google Is On Guard Sharks Shall Not Pass (report)
  • blog.fox-it.com — Sharkbot A New Generation Android Banking Trojan Being Distributed On Google Play Store (report)
  • blog.fox-it.com — Sharkbot Is Back In Google Play (report)
  • MITRE ATT&CK — S1055 (report)

External references