Alien
Aliases: AlienBot
- First seen
- 2020-01-01 00:00:00
- Malware type
- trojan, rat, botnet
- Family
- Malware family
- Last IoC activity
- 2026-07-21 22:35:20
- Profile updated
- 2026-07-07 14:03:23
Targeted industries: financial-services
Context
According to ThreatFabric, this is a fork of Cerberus v1 (active January 2020+). Alien is a rented banking trojan that can remotely control a phone and achieves RAT functionality by abusing TeamViewer.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Alien (report)
- threatfabric.com — Alien The Story Of Cerberus Demise (report)
- prodaft.com — Brunhilda Daas (report)
- resecurity.com — In The Box Mobile Malware Webinjects Marketplace (report)
- preyproject.com — Cerberus And Alien The Malware That Has Put Android In A Tight Spot (report)
- muha2xmad.github.io — Alien (report)
- research.checkpoint.com — Clast82 A New Dropper On Google Play Dropping The Alienbot Banker And Mrat (report)
- checkpoint.com — March 2022S Most Wanted Malware Easter Phishing Scams Help Emotet Assert Its Dominance (report)
- twitter.com — 1603375823448317953 (report)
- drive.google.com — View (report)
- info.phishlabs.com — Alien Mobile Malware Evades Detection Increases Targets (report)
- bleepingcomputer.com — Google Predator Spyware Infected Android Devices Using Zero Days (report)
- threatfabric.com — Deceive The Heavens To Cross The Sea (report)