Xenomorph is an Android banking trojan associated with the Hadoken group and first publicly identified in 2022. It targets mobile banking, payment, email, and cryptocurrency applications, initially focusing on European institutions and later expanding to hundreds of financial targets across multiple regions. The malware is designed to steal credentials and facilitate account takeover by abusing Android Accessibility Services, presenting overlay screens on top of legitimate applications, intercepting SMS messages and notifications, and collecting device and application inventory data from infected phones.
Xenomorph has been distributed through multiple Android delivery chains, including malicious or trojanized applications on Google Play, droppers such as GymDrop and BugDrop, and app-binding services such as Zombinder that attach the payload to otherwise functional legitimate apps. Observed lures have included cleaner utilities, task-management and expense apps, QR-code readers, fake updates, counterfeit Play Protect prompts, and trojanized popular Android applications. Some campaigns used Firebase-controlled staging logic or downloader components to retrieve the banking payload after installation.
Operationally, Xenomorph communicates with command-and-control infrastructure to register infected devices, upload installed-app lists, receive target-specific overlays, and execute commands. Across observed versions, supported functions include overlay injection control, SMS logging and interception, notification interception, application listing, application termination, self-removal, SMS sending, USSD execution, call-forwarding-related actions, SOCKS proxy support, and cookie handling. Newer variants added keylogging, remote-action capabilities driven by Accessibility Services, and runtime modules that enable gesture execution and broader remote interaction on the device.
A major evolution of the malware introduced a full Automated Transfer System framework. This allows operators to automate fraudulent workflows directly on the victim device, including credential harvesting, balance checking, transaction initiation, MFA interception, and transfer completion. Later variants also added session-cookie theft by extracting web session data from Android components, increasing the malware’s usefulness beyond simple credential phishing. These enhancements moved Xenomorph from a conventional overlay-based banking trojan toward a more capable fraud platform with remote-access characteristics.
Xenomorph has shown signs of active development and modular engineering, with multiple codebase revisions, runtime extensibility, and changing distribution infrastructure. It has been linked to campaigns targeting banking customers in countries including Spain, Portugal, Italy, Belgium, and Canada, and later to broader target sets exceeding 400 financial institutions and cryptocurrency services. Its combination of Accessibility abuse, credential theft, MFA interception, session theft, and ATS-driven fraud automation makes it one of the more advanced Android banking malware families observed in recent years.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These new campaigns feature a new and improved version of Xenomorph, which added RAT capabilities thanks to the addition of a handful of... 'Runtime modules'.
The latest campaign we identified while writing the blog involving Zombinder was distributing Xenomorph banking trojan under the guise of VidMate application.
The main product of this group is Xenomorph, a Android banking trojan discovered by ThreatFabric in February 2022.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
It was distributed through a fake one-page website containing only two buttons... the “Download for Android” button leads to downloading samples of Ermac... modified legitimate application was downloaded from malicious website mimicking the original website of the application. Victim is navigated there through malicious advertisement.
The malware will periodically poll for new commands from the C2, receiving the following response: { "type" : "get_coms" , "coms" : [ "<COMMANDS>" ] }
Xenomorph, just like the other malware families previously mentioned, starts a browser with JavaScript interface enabled.
DexClassLoader is used in a single place... This method loads dynamically the decrypted payload stored on the filesystem in “filename”
Here the banking payload has the Telegram page link encoded with RC4 encryption... ThreatLabz also observed RC4 encoded C2 domains stored inside the code.
after installation, the bot will always request overlays from the C2, which will send back an encrypted JSON configuration, with the URLs where the overlays are hosted.
Ermac.C, having the following capabilities... Keylogging... It is worth noting that authors of Xenomorph... enhanced with keylogging functionality
Xenomorph creates an overlay onto legit banking applications to trick users into entering their credentials.
It is also capable of intercepting users’ SMS messages and notifications, enabling it to steal one-time passwords and multifactor authentication requests.
after installation, the bot will always request overlays from the C2, which will send back an encrypted JSON configuration, with the URLs where the overlays are hosted.
This banking malware later reaches out to the command-and-control (C2) servers decoded either via Telegram page content or from a static code routine to request further commands, extending the infection.
Upon successful login, the browser will extract the cookie using the Android CookieManager and will send it to the C2 server
Latest versions of it are enhanced with keylogging functionality, accessibility actions engine as well as SOCKS proxy feature.
When the app is first opened, it reaches out to a Firebase server to get the stage/banking malware payload URL. It then downloads the malicious Xenomorph banking trojan samples from Github.
The screenshots in Figures 6 and 7 below show the C2 retrieval from a Telegram page. Here the banking payload has the Telegram page link encoded with RC4 encryption. Upon execution, the banking payload will reach out to the Telegram page and download the content hosted on that page.
143 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan embedded in Google Play apps that steals banking credentials, intercepts SMS messages and notifications to capture OTP/MFA prompts, abuses accessibility/device admin privileges for persistence, downloads payloads from GitHub, retrieves C2 information via Telegram or static encrypted routines, and uses overlays on legitimate banking apps to phish credentials.
Android banking malware using an Automated Transfer System (ATS) to bypass MFA and automate fraudulent transactions; steals credentials and data from banking apps and crypto wallets; newer versions steal session cookies; distributed via trojanized apps and a service called 'Zombinder'.
Android banking trojan focused on mobile fraud. The latest variant adds an Accessibility Services-powered runtime engine and a full ATS framework to automate the fraud chain, including credential/PII theft via overlays and keylogging, transaction automation, MFA code theft, cookie stealing, SMS interception, app control, and funds exfiltration.
Android banking trojan distributed via Zombinder; newer versions add keylogging, an accessibility actions engine, and a SOCKS proxy feature.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.