Xenomorph

Malware type
rat, trojan, credential-stealer
Family
Malware family
Last IoC activity
2026-07-21 06:51:10
Profile updated
2026-07-07 14:06:01

Targeted industries: financial-services

Context

Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Trojan_Android_Xenomorph (yara-rule)

Reports & references

  • threatfabric.com — Zombinder Ermac And Desktop Stealers (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Xenomorph (report)
  • cryptax.medium.com — Unpacking A Jsonpacker Packed Sample 4038E12119F5 (report)
  • threatfabric.com — Xenomorph A Newly Hatched Banking Trojan (report)
  • zscaler.com — Rise Banking Trojan Dropper Google Play 0 (report)
  • threatfabric.com — Bugdrop New Dropper Bypassing Google Security Measures (report)
  • threatfabric.com — Xenomorph V3 New Variant With Ats (report)

External references