Xenomorph
- Malware type
- rat, trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-21 06:51:10
- Profile updated
- 2026-07-07 14:06:01
Targeted industries: financial-services
Context
Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor.
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Trojan_Android_Xenomorph (yara-rule)
Reports & references
- threatfabric.com — Zombinder Ermac And Desktop Stealers (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Xenomorph (report)
- cryptax.medium.com — Unpacking A Jsonpacker Packed Sample 4038E12119F5 (report)
- threatfabric.com — Xenomorph A Newly Hatched Banking Trojan (report)
- zscaler.com — Rise Banking Trojan Dropper Google Play 0 (report)
- threatfabric.com — Bugdrop New Dropper Bypassing Google Security Measures (report)
- threatfabric.com — Xenomorph V3 New Variant With Ats (report)