Coper is an Android banking trojan descended from the Exobot/ExobotCompact lineage and is also widely associated with the Octo name in later reporting. First observed in 2021 targeting Colombian Android users, it evolved into a modular, multi-stage malware family used against banking customers in Europe, Turkey, Australia, parts of South America, and other regions. It is commonly distributed through trojanized Android applications that impersonate banking, security, utility, browser, or Google Play-related apps, including campaigns involving official app marketplaces, fraudulent landing pages, and SMS-based lures.
Coper typically begins as a dropper or loader application that requests extensive permissions and then decrypts and loads additional malicious code at runtime, often through native libraries and encrypted DEX payloads. It heavily abuses Android Accessibility Services to automate user-interface interaction, grant itself privileges, harvest on-screen content, and enable remote fraud. Observed variants also use Device Administration, notification access, SMS permissions, and background execution features to resist removal and maintain control of the device.
Its core functionality centers on banking fraud and credential theft. Capabilities documented across variants include overlay and webinject-based credential harvesting against banking applications, keylogging, interception of SMS messages and push notifications, theft of one-time passwords, collection of installed-app inventories and device metadata, and suppression of notifications to hide malicious activity. More advanced builds support VNC-like remote control or on-device fraud workflows, allowing operators to view screen contents, simulate taps and gestures, launch apps or URLs, lock the device, uninstall applications, and interact with targeted banking sessions in real time.
Coper employs multiple defensive and anti-analysis measures. These include encrypted strings and payloads, encrypted command-and-control traffic, integrity checks, restoration of removed components, repeated prompting for sensitive permissions, hiding launcher icons, monitoring attempts to revoke Accessibility or administrator privileges, and checks for emulators or other analysis environments in some variants. Several analyses also describe server-side victim filtering and geofencing behavior.
The malware has been linked to malware-as-a-service activity, with reporting indicating builder and panel infrastructure and possible overlap with operators active in Turkey. Campaigns have repeatedly targeted financial institutions and their customers, with especially notable activity reported in Turkey. Coper remains one of the more prominent Android banking trojans due to its combination of credential theft, SMS interception, remote device control, persistence, and anti-removal tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
These apps, which pose as Play Store app installer, screen recording, and financial apps, are "powered by inventive distribution schemes," distributing them through the Google Play store and via fraudulent landing pages that purportedly alert users to download a browser update.
Il ciclo è effettuato con una sveglia (alarm) ripetuta ogni 60 secondi ed in grado di svegliare il telefono (RTC_WAKE).
the operator can further interact with the malware using a series of commands. All requests to/from the C2 infrastructure are AES encrypted and Base64 encoded.
Il ciclo è effettuato con una sveglia (alarm) ripetuta ogni 60 secondi ed in grado di svegliare il telefono (RTC_WAKE).
Il ciclo è effettuato con una sveglia (alarm) ripetuta ogni 60 secondi ed in grado di svegliare il telefono (RTC_WAKE).
The droppers, once installed, act as a conduit to launch the trojans, but not before requesting users to enable the Accessibility Services that allow it a wide breadth of capabilities to exfiltrate sensitive information from the compromised phones.
Un Receiver che fa da raccoglitore di eventi del sistema (avvio, connettività, installazione e rimozione applicazioni, presenza dell’utente, stato dello schermo).
Accessibility Index: Displays instructions on how to enable Accessibility Services, which are required to be activated in order to facilitate remote interactions with the infected device. A degree of social engineering is employed to encourage the victim to take this action
To evade detection, all the strings within the class, cermb.dex are encrypted with RC4 key “ Pyae9UJ8swZDJz2KI “
To evade detection, all Dex classes associated with Coper/Octo are encrypted using a hardcoded RC4 key
this malicious apk decrypts the malicious payload file called “cermb” from the app’s assets folder to an executable dex format named ‘cermb.dex’ and loads the decrypted file
Other notable features of Octo include... persistence measures to prevent uninstallation and evade antivirus engines.
Funziona da keylogger ... Inoltre Coper ha una funzionalità apposita per il furto del PIN/password/pattern per lo sblocco dello schermo.
Poza mechanizmem webinjectów Coper pozwala m.in na przechwytywanie i wysyłanie SMSów, czy uruchomienie keyloggera.
URL Inject: Displays an overlay web page, such as an authentication form, when the victim user accesses an app. The URL inject allows for the harvesting of credentials from any accounts or applications the operator wishes to target.
MITRE ATT&CK Tactics Techniques... Discovery System Network Configuration Discovery
MITRE ATT&CK Tactics Techniques... Discovery... System Information Discovery
Other notable features of Octo include... persistence measures to prevent uninstallation and evade antivirus engines.
Nel primo ping (di registrazione) sono inviate varie informazioni sul dispositivo, tra cui lingua e paese. Il C2 può, nella sua risposta, indicare di indurre l’utente ad installare il servizio di accessibilità.
Funziona da keylogger ... Inoltre Coper ha una funzionalità apposita per il furto del PIN/password/pattern per lo sblocco dello schermo.
Poza mechanizmem webinjectów Coper pozwala m.in na przechwytywanie i wysyłanie SMSów, czy uruchomienie keyloggera.
Coper/Octo operates through a complex command-and-control (C2) infrastructure, encrypting communications to evade detection.
this application downloads malicious Coper malware file com.lastcarn_PlayMarket.apk... the malware file “com.lastcarn_PlayMarket.apk” gets downloaded from a GitHub repository
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan (BankBot lineage) active in Turkey; steals SMS content (including banking verification codes) and related sensitive data.
Banking trojan family active in 2025; specific behaviors not detailed here beyond being a banking trojan (elsewhere referenced as stealing SMS contents).
Android banking trojan masquerading as the PKO BP IKO banking app. It abuses accessibility services to take over the device, can imitate user actions, steal data via webinjects, intercept and send SMS messages, and enable a keylogger. The sample analyzed also used encrypted payloads and communicated with C2 servers using AES/ECB and Base64-encoded traffic.
Banking trojan previously observed in malicious Google Play apps with a similar infection chain, including payload retrieval from GitHub.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.