S.O.V.A.

MITRE ATT&CK: S1062 View on attack.mitre.org

Aliases: S.O.V.A.

First seen
2021-08-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
android
Related IoCs
12 (10 malicious)
Last IoC activity
2026-08-24 04:59:49
Profile updated
2026-07-07 14:08:38

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

S.O.V.A. is an Android banking trojan that was first identified in August 2021 and has subsequently been found in a variety of applications, including banking, cryptocurrency wallet/exchange, and shopping apps. S.O.V.A., which is Russian for "owl", contains features not commonly found in Android malware, such as session cookie theft.

Recent IoC activity

10 malicious indicators in Maltiverse are attributed to S.O.V.A. (S1062). The 10 most recently updated:

Malware & tools used

  • Software Discovery (attack-pattern)
  • Input Injection (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • SMS Messages (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Screen Capture (attack-pattern)
  • Network Denial of Service (attack-pattern)
  • Uninstall Malicious Application (attack-pattern)
  • Keylogging (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Access Notifications (attack-pattern)
  • Software Packing (attack-pattern)
  • Transmitted Data Manipulation (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • SMS Control (attack-pattern)
  • Prevent Application Removal (attack-pattern)
  • Web Protocols (attack-pattern)
  • Adversary-in-the-Middle (attack-pattern)

Reports & references

  • liansecurity.com (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Sova (report)
  • blog.cyble.com — Nexus The Latest Android Banking Trojan With Sova Connections (report)
  • cleafy.com — Sova Malware Is Back And Is Evolving Rapidly (report)
  • cryptax.medium.com — Eyes On Android S O V A Botnet Sample Fb5Ed332D08 (report)
  • blog.cyble.com — Deep Dive Analysis Of S O V A Android Banking Trojan (report)
  • muha2xmad.github.io — Sova (report)
  • threatfabric.com — Sova New Trojan With Fowl Intentions (report)
  • MITRE ATT&CK — S1062 (report)

External references