Svpeng is a long-running Android banking malware family active since at least 2013 and regarded as one of the earlier mobile threats to target SMS banking. It is primarily associated with credential theft and financial fraud on Android devices, but some variants have also incorporated screen-locking or ransomware-style blocking behavior. The family has remained prominent in Android banking-malware telemetry for multiple years.
Svpeng is known for abusing Android accessibility services to obtain extensive privileges, automate malicious actions, and interfere with user attempts to remove it. Documented variants can grant themselves device administrator rights, assign themselves as the default SMS application, obtain permissions to send and receive SMS, make calls, and read contacts, and resist uninstallation by blocking changes to administrator settings. Accessibility abuse also enables the malware to inspect user-interface content in other applications and determine which app is currently in the foreground.
Its core tradecraft includes stealing financial data through phishing overlays and interception of user input. A notable 2017 variant added keylogging functionality by capturing entered text via accessibility services and, in some cases, taking screenshots during keyboard activity to exfiltrate sensitive information from targeted applications. Where screenshot capture is ineffective, Svpeng can fall back to overlay-based credential theft against banking and other financial or payment-related apps. Observed command capabilities include collecting SMS messages, contacts, call logs, and installed-app information, opening URLs, and stealing incoming SMS, supporting both account takeover and transaction fraud.
Svpeng has been distributed through malicious websites masquerading as legitimate software updates, including fake Flash Player lures, and has also been observed using online advertising infrastructure for distribution. The family has targeted users across numerous countries and has shown broad interest in banking, payment, e-commerce, and related consumer applications. Some variants reportedly avoid execution on devices configured for Russian language, a behavior commonly interpreted as regional self-exclusion by Russian-speaking cybercriminal operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
This study analyzes the banking malware that steals the credentials used to access online banking or payment system accounts and to intercept one-time passwords.
This study analyzes the banking malware that steals the credentials used to access online banking or payment system accounts and to intercept one-time passwords.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android ransomware Trojan family listed among the most detected mobile ransomware threats in Q3 2025.
A mobile banking Trojan family that remained active enough to appear in the top 10 mobile bankers list.
Mobile malware family appearing both as ransomware and banking Trojan in the report; widely encountered and especially prevalent in ransomware statistics for the US and Iran.
Android banking Trojan focused largely on obtaining administrator rights on infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.