Hydra is an Android banking trojan focused on credential theft and fraud against mobile banking, payment, and cryptocurrency users. It is known for overlay-based phishing against targeted applications, abuse of Android Accessibility Services to automate malicious actions and resist removal, interception of SMS messages and one-time passwords, theft of cookies and other device data, and support for broader post-compromise actions such as contact harvesting, notification interception, call-forwarding manipulation, USSD abuse, and bulk SMS propagation. Multiple analyses have shown Hydra using packing and dynamic code-loading techniques, including DexClassLoader-based payload loading, anti-emulation checks, obfuscated strings, and staged payload extraction from embedded resources, all of which complicate analysis and detection.
Hydra has repeatedly been distributed through staged Android infection chains rather than overtly malicious first-stage apps. Observed delivery methods include trojanized applications on Google Play posing as utilities such as document scanners, QR-related tools, and other benign-looking apps; fake update prompts that trick users into sideloading a second-stage payload; phishing sites; and third-party droppers such as Brunhilda and DawDropper. Campaigns have selectively targeted users by geography and installed-app profiling, and Hydra activity has been reported against banking users in regions including Turkey, Colombia, Europe, and the United States.
Operationally, Hydra is part of the broader Android banking-malware ecosystem alongside families such as Anubis, Cerberus, Ermac, Octo, and SharkBot. It supports webinject and overlay workflows used to impersonate legitimate financial and other applications, enabling theft of credentials, session material, and authentication data that can be used for account takeover and fraudulent transactions. Hydra has also been referenced as a base or inspiration for bespoke Android malware used in targeted operations, underscoring its adaptability beyond commodity banking fraud. Overall, Hydra is a mature Android bankbot family characterized by staged delivery, strong anti-analysis measures, and a blend of credential theft, session abuse, and device-level control features tailored for mobile financial fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the first case, we observed Brunhilda posing as a QR code creator app, Brunhilda dropped samples from established families, like Hydra, as well as novel ones, like Ermac.
"...GREYBATTLE, a bespoke version of the Hydra banking trojan..."
"...GREYBATTLE, a bespoke version of the Hydra banking trojan..."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Dropper apps extract dex file from png file with kinda stenography and downloads malicious app from command and control server with dropped dex.
These apps posed as QR code scanners, PDF scanners, and cryptocurrency apps.
If you look for dropped file in filesystem, you won’t see anything. File is removed with remove .
Using the discovered wordlist with Hydra, valid credentials are obtained through a brute-force attack. With authenticated WordPress access...
As you can see there are functions : getSimCountryISO , getNetworkCountryIso , getCountry and one suspicious string : tr . Without running we can assume code will check if these function’s return values are equals to tr . I know this app targets Turkish people so this is reasonable to avoid sandbox and even manual analyze.
the threat actor was observed dropping and executing open source and free tools such as Hydra, SecretsDump, and CrackMapExec.
Hydra is another android bankbot variant. It uses overlay to steal information like Anubis.
Using the discovered wordlist with Hydra, valid credentials are obtained through a brute-force attack.
The threat actors then likely used password-cracking techniques to obtain the plaintext password.
Among the new tools are additions focused on credential testing, including legba and the re-added hydra-gtk. Their inclusion reflects how identity-based attacks—including password spraying, credential reuse, and authentication testing—continue to play a central role in modern security assessments.
As you can see there are functions : getSimCountryISO , getNetworkCountryIso , getCountry and one suspicious string : tr . Without running we can assume code will check if these function’s return values are equals to tr . I know this app targets Turkish people so this is reasonable to avoid sandbox and even manual analyze.
Dropper apps extract dex file from png file with kinda stenography and downloads malicious app from command and control server with dropped dex.
Hydra invece permette di monitorare la navigazione online, individuando le applicazioni usate, i siti web visitati, e se si fa uso di VPN o del Tor Browser
In this moment, Anatsa payload is downloaded from the C2 server(s), and installed on the device of the unsuspecting victim.
88 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan family referenced as the base code/family for the bespoke Android malware GREYBATTLE.
A banking trojan family referenced as part of ongoing financially motivated campaigns targeting banking and financial credentials.
Mobile banking malware family mentioned as supporting webinjects for credential interception and theft.
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.