S.O.V.A.
MITRE ATT&CK: S1062 View on attack.mitre.org
Aliases: S.O.V.A.
- First seen
- 2021-08-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 12 (10 malicious)
- Last IoC activity
- 2026-08-24 04:59:49
- Profile updated
- 2026-07-07 14:08:38
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
S.O.V.A. is an Android banking trojan that was first identified in August 2021 and has subsequently been found in a variety of applications, including banking, cryptocurrency wallet/exchange, and shopping apps. S.O.V.A., which is Russian for "owl", contains features not commonly found in Android malware, such as session cookie theft.
Recent IoC activity
10 malicious indicators in Maltiverse are attributed to S.O.V.A. (S1062). The 10 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 493f24d7e8543ad526e6e30cd6e23b7d71d4391d2534d48cd54099697e85e53f | 2026-04-22 | 1 |
| file sample | b5fe7385acde76459ebc61edaf6b510f9c6d42b4c54cba565b232670985f4bce | 2026-04-20 | 1 |
| file sample | 182cc43b2817250ebd80a116f82a7a410ded22ea12821ca192f8a8d29d3b0b09 | 2026-04-17 | 1 |
| file sample | f68896d4dbb535e0bac2d51448be3cd959d3ab1d64284826d9d4199f8251639e | 2026-04-16 | 1 |
| file sample | 546bc8d7b0386e95c231dff26cc755fc241bdea33243691625ec63a0a3a9487e | 2026-04-14 | 1 |
| file sample | d5cad5cc6147eb82ec39c58b08348e61c2391fcf6aee1038744091dc0814a70f | 2026-04-12 | 1 |
| file sample | e9c42b55b2bfb18bb62858fa306c0aca8aad41764ffe7eac76def46ef83470e8 | 2026-04-07 | 1 |
| file sample | b7c94b8a0562ad87bd7f5764dd5b416f6cd267dec46f5157160477eb68a8bcc7 | 2026-04-01 | 1 |
| file sample | dcd04daa033f25e662b75edc4764657db033782c3191baa973d6c2da3f0f0d95 | 2026-03-31 | 1 |
| file sample | 74b780ed98cac6b72fd82d3260e216cd19968ba0d470f3934e618272f174c41a | 2026-03-28 | 1 |
Malware & tools used
- Software Discovery (attack-pattern)
- Input Injection (attack-pattern)
- GUI Input Capture (attack-pattern)
- SMS Messages (attack-pattern)
- Stored Application Data (attack-pattern)
- Screen Capture (attack-pattern)
- Network Denial of Service (attack-pattern)
- Uninstall Malicious Application (attack-pattern)
- Keylogging (attack-pattern)
- Suppress Application Icon (attack-pattern)
- System Information Discovery (attack-pattern)
- Access Notifications (attack-pattern)
- Software Packing (attack-pattern)
- Transmitted Data Manipulation (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- SMS Control (attack-pattern)
- Prevent Application Removal (attack-pattern)
- Web Protocols (attack-pattern)
- Adversary-in-the-Middle (attack-pattern)
Reports & references
- liansecurity.com (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Sova (report)
- blog.cyble.com — Nexus The Latest Android Banking Trojan With Sova Connections (report)
- cleafy.com — Sova Malware Is Back And Is Evolving Rapidly (report)
- cryptax.medium.com — Eyes On Android S O V A Botnet Sample Fb5Ed332D08 (report)
- blog.cyble.com — Deep Dive Analysis Of S O V A Android Banking Trojan (report)
- muha2xmad.github.io — Sova (report)
- threatfabric.com — Sova New Trojan With Fowl Intentions (report)
- MITRE ATT&CK — S1062 (report)