Antidot
- Malware type
- credential-stealer, keylogger, trojan
- Last IoC activity
- 2026-07-21 04:38:14
- Profile updated
- 2026-07-07 14:03:54
Targeted regions: country_code:de country_code:fr country_code:es country_code:ru country_code:pt country_code:ro country_code:us
Context
The malware displays fake Google Play update pages in multiple languages, including German, French, Spanish, Russian, Portuguese, Romanian, and English, indicating potential targets in these regions. Antidot uses overlay attacks and keylogging techniques to efficiently collect sensitive information such as login credentials.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Antidot (report)
- catalyst.prodaft.com — Overview (report)
- cyble.com — New Antidot Android Banking Trojan Masquerading As Google Play Updates (report)
- medium.com — Two Tales And One Antidot E A New Mobile Malware Campaign In Poland De704997096F (report)