Vultur

Aliases: Vulture

First seen
2021-06-01 00:00:00
Malware type
trojan, screen-capture, credential-stealer
Family
Malware family
Last IoC activity
2026-05-26 05:25:04
Profile updated
2026-07-07 14:04:44

Targeted industries: financial-services

Context

Vultur is an Android banking trojan that primarily targets financial services. It uses screen overlay techniques to capture sensitive information entered by users on affected devices. Identified in mid-2021, it focuses on stealing credentials and has various capabilities to silently monitor user interactions.

Reports & references

  • cleafy.com — The Android Malwares Journey From Google Play To Banking Fraud (report)
  • threatfabric.com — The Attack Of The Droppers (report)
  • blog.fox-it.com — Android Malware Vultur Expands Its Wingspan (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Vultur (report)
  • threatfabric.com — Vultur V For Vnc (report)
  • twitter.com — 1485651238175846400 (report)
  • embeeresearch.io — Infrastructure Tracking Locating Vultur Domains With Passive Dns (report)

External references