FluBot
MITRE ATT&CK: S1067 View on attack.mitre.org
Aliases: Cabassous, FakeChat, FluBot
- First seen
- 2020-11-01 00:00:00
- Malware type
- trojan, credential-stealer, botnet
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 189 (120 malicious)
- Last IoC activity
- 2026-08-31 08:52:47
- Profile updated
- 2026-07-07 13:52:06
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Targeted regions: country_code:es country_code:de country_code:uk country_code:fi country_code:dk
Context
FluBot is a multi-purpose mobile banking malware that was first observed in Spain in late 2020. It primarily spread through European countries using a variety of SMS phishing messages in multiple languages. An international law enforcement operation of 11 countries eventually disrupted the spread of FluBot.
Recent IoC activity
121 malicious indicators in Maltiverse are attributed to FluBot (S1067). The 20 most recently updated:
Malware & tools used
- SMS Control (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
- Contact List (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Stored Application Data (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- GUI Input Capture (attack-pattern)
- Phishing (attack-pattern)
- Proxy Through Victim (attack-pattern)
- Web Protocols (attack-pattern)
- User Evasion (attack-pattern)
- Abuse Accessibility Features (attack-pattern)
- SMS Messages (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Access Notifications (attack-pattern)
- Prevent Application Removal (attack-pattern)
Reports & references
- threatfabric.com — Partners In Crime Medusa Cabassous (report)
- checkpoint.com — March 2022S Most Wanted Malware Easter Phishing Scams Help Emotet Assert Its Dominance (report)
- bitdefender.com — New Flubot And Teabot Global Malware Campaigns Discovered (report)
- labs.bitdefender.com — Threat Actors Use Mockups Of Popular Apps To Spread Teabot And Flubot Malware On Android (report)
- thehackernews.com — Widespread Flubot And Teabot Malware (report)
- telekom.com — Flubot Under The Microscope 636368 (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Flubot (report)
- medium.com — The Brief Glory Of Cabassous Flubot A Private Android Banking Botnet Bc2Ed7917027 (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- blog.nviso.eu — How To Analyze Mobile Malware A Cabassous Flubot Case Study (report)
- proofpoint.com — Flubot Android Malware Spreading Rapidly Through Europe May Hit Us Soon (report)
- twitter.com — 1395675479194095618 (report)
- blog.zimperium.com — Flubot Vs Zimperium (report)
- europol.europa.eu — Takedown Of Sms Based Flubot Spyware Infecting Android Phones (report)
- blog.cyble.com — Flubot Variant Masquerading As The Default Android Voicemail App (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- blog.fox-it.com — Flubot The Evolution Of A Notorious Android Banking Malware (report)
- twitter.com — 1404098461440659459 (report)
- twitter.com — 1402615237296148483 (report)
- news.netcraft.com — Flubot Malware Spreads To Australia (report)