Alien

Aliases: AlienBot

First seen
2020-01-01 00:00:00
Malware type
trojan, rat, botnet
Family
Malware family
Last IoC activity
2026-07-21 22:35:20
Profile updated
2026-07-07 14:03:23

Targeted industries: financial-services

Context

According to ThreatFabric, this is a fork of Cerberus v1 (active January 2020+). Alien is a rented banking trojan that can remotely control a phone and achieves RAT functionality by abusing TeamViewer.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Alien (report)
  • threatfabric.com — Alien The Story Of Cerberus Demise (report)
  • prodaft.com — Brunhilda Daas (report)
  • resecurity.com — In The Box Mobile Malware Webinjects Marketplace (report)
  • preyproject.com — Cerberus And Alien The Malware That Has Put Android In A Tight Spot (report)
  • muha2xmad.github.io — Alien (report)
  • research.checkpoint.com — Clast82 A New Dropper On Google Play Dropping The Alienbot Banker And Mrat (report)
  • checkpoint.com — March 2022S Most Wanted Malware Easter Phishing Scams Help Emotet Assert Its Dominance (report)
  • twitter.com — 1603375823448317953 (report)
  • drive.google.com — View (report)
  • info.phishlabs.com — Alien Mobile Malware Evades Detection Increases Targets (report)
  • bleepingcomputer.com — Google Predator Spyware Infected Android Devices Using Zero Days (report)
  • threatfabric.com — Deceive The Heavens To Cross The Sea (report)

External references