Vultur
Aliases: Vulture
- First seen
- 2021-06-01 00:00:00
- Malware type
- trojan, screen-capture, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-05-26 05:25:04
- Profile updated
- 2026-07-07 14:04:44
Targeted industries: financial-services
Context
Vultur is an Android banking trojan that primarily targets financial services. It uses screen overlay techniques to capture sensitive information entered by users on affected devices. Identified in mid-2021, it focuses on stealing credentials and has various capabilities to silently monitor user interactions.
Reports & references
- cleafy.com — The Android Malwares Journey From Google Play To Banking Fraud (report)
- threatfabric.com — The Attack Of The Droppers (report)
- blog.fox-it.com — Android Malware Vultur Expands Its Wingspan (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Vultur (report)
- threatfabric.com — Vultur V For Vnc (report)
- twitter.com — 1485651238175846400 (report)
- embeeresearch.io — Infrastructure Tracking Locating Vultur Domains With Passive Dns (report)