Antidot

Malware type
credential-stealer, keylogger, trojan
Last IoC activity
2026-07-21 04:38:14
Profile updated
2026-07-07 14:03:54

Targeted regions: country_code:de country_code:fr country_code:es country_code:ru country_code:pt country_code:ro country_code:us

Context

The malware displays fake Google Play update pages in multiple languages, including German, French, Spanish, Russian, Portuguese, Romanian, and English, indicating potential targets in these regions. Antidot uses overlay attacks and keylogging techniques to efficiently collect sensitive information such as login credentials.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Antidot (report)
  • catalyst.prodaft.com — Overview (report)
  • cyble.com — New Antidot Android Banking Trojan Masquerading As Google Play Updates (report)
  • medium.com — Two Tales And One Antidot E A New Mobile Malware Campaign In Poland De704997096F (report)

External references