Marcher is an Android banking Trojan active since at least the mid-2010s and widely associated with credential theft against mobile banking users. It is known for phishing-style overlay attacks that place fraudulent login or payment prompts on top of legitimate banking applications and other trusted Android apps, including app-store interfaces, to capture usernames, passwords, payment-card data, and related verification information. Marcher has also been described as password-stealing malware and has been sold in Russian-language underground markets.
Marcher is delivered through social-engineering-heavy Android sideloading schemes rather than trusted app stores. Observed delivery methods include links sent by SMS and email, phishing campaigns targeting bank customers, fake security or update applications, and lures themed around popular brands or software. Campaigns have instructed victims to enable installation from unknown sources and, in some cases, to grant elevated Android privileges such as device administrator access. It has also appeared in fake update traffic-redirect chains that deliver different payloads depending on device type.
The malware primarily targets Android users of financial institutions, with documented campaigns against banking customers in countries including Austria and Australia. It has also been used to target payment-related workflows by harvesting card data through overlays shown over legitimate applications. Marcher has been linked to broader criminal distribution ecosystems, including Avalanche-hosted malware operations, and to infrastructure overlaps with other financially motivated malware activity.
Marcher is significant in the Android banking-malware lineage because later families such as Exobot and Gustuff were reported to derive from or build on Marcher code or tradecraft. Its long-running use of overlay-based credential theft made it a representative example of mobile input-prompt abuse against banking apps.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
However, if a user was on an Android device, they would be given the same fake update redirect and download instructions, but the payload would be the Marcher banking trojan.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Typically, an attack chain will consist of three parts: the malicious injects served to website visitors, which are often malicious JavaScript scripts; a traffic distribution service (TDS) responsible for determining what user gets which payload based on a variety of filtering options; and the ultimate payload that is downloaded by the script.
The attacks described here begin with a banking credential phishing scheme, followed by an attempt to trick the victim into installing Marcher, and finally with attempts to steal credit card information by the banking Trojan itself.
Analysis of the malware shows that it uses the common string obfuscation of character replacement (Figure 7).
The botnet implements all the typical features that banking trojans currently have: overlay injection over mobile banking applications...
The link leads to a phishing page that asks for banking login credentials or an account number and PIN.
In addition to operating as a banking Trojan, overlaying a legitimate banking app with an indistinguishable credential theft page...
The botnet implements all the typical features that banking trojans currently have: overlay injection over mobile banking applications...
64 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan referenced as part of TA2727-associated activity set.
Previously observed Android trojan variant impersonating the Super Mario Run game.
Android banking trojan referenced as a TA2727 payload delivered via Keitaro TDS traffic flows discussed alongside SocGholish delivery chains.
An Android banking trojan delivered by TA2727 through fake update web injects. The report notes it has targeted Android devices since 2013.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.