SharkBot is an Android banking trojan first identified in late 2021 that targets banking and financial users through credential theft, SMS interception, overlay-based phishing, and automated fraud. It is notable among mobile banking malware for combining heavy abuse of Android Accessibility Services with a resilient command-and-control design that includes a fallback domain generation algorithm. SharkBot has been distributed through malicious Android applications masquerading as antivirus, cleaner, file-management, or tax-related tools, including campaigns that abused Google Play to reach large numbers of victims. Operators have used geographic filtering and targeted-app checks to limit payload delivery to selected countries and banking ecosystems.
After installation, SharkBot seeks Accessibility permissions and uses them to observe foreground applications, capture user-interface events, click permission dialogs, interfere with removal, and automate interactions inside targeted apps. Core capabilities documented across versions include credential theft, banking-information theft, keylogging via accessibility events, overlay attacks, SMS reading and interception, SMS sending and hiding, contact theft, and exfiltration of captured credentials and event logs to command-and-control infrastructure over HTTP. SharkBot can also alter SMS-handling behavior on the device, maintain persistence by hiding its icon and resisting battery-optimization limits, and download additional modules that extend functionality while complicating analysis.
Later SharkBot variants expanded beyond classic overlay fraud. Version 2 introduced substantial refactoring, changes to communications, and updated DGA logic. Subsequent releases added cookie theft by opening attacker-controlled WebView content and extracting authenticated session cookies after victims logged into targeted services. SharkBot also supports ATS-style fraud automation, using Accessibility-driven remote actions to navigate banking workflows, bypass some login flows, and initiate fraudulent transactions directly on the victim device. Some configurations shifted from traditional web injections toward keylogging and text capture against selected banking applications.
Operational reporting has linked SharkBot to repeated campaigns focused especially on Italy and the United Kingdom, with later expansion to additional countries in Europe, North America, and Australia. Multiple analyses have assessed the malware as an actively evolving private mobile banking operation rather than a commodity family in its earliest stages. Its combination of Accessibility abuse, SMS interception, modular updates, geofencing, anti-analysis checks, DGA-backed resilience, and session-cookie theft has made SharkBot one of the more capable Android banking trojans observed in the 2021-2022 period.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
the very first samples tracked down at the end of October use: a demo version of the Allatori Java Obfuscation
SharkBot hides itself with common names and icons posing as a legitimate application to the victims
removeApp ... the server sends a huge list of applications which should be uninstalled from the user’s device.
Sharkbot lures victims to enter their credentials in windows that mimic benign credential input forms. When the user enters credentials in these windows, the compromised data is sent to a malicious server.
Keylogging: this feature allows Sharkbot to receive every accessibility event produced in the infected device, this way, it can log events such as button clicks, changes in TextFields
SharkBot is able to read/send text messages, perform overlay attacks
CherryBlos has exfiltrated credentials collected from pictures that have been analyzed using optical character recognition (OCR).
Once the victim logged in to his bank account, the malware will receive the PageFinished event and will get the cookies of the website loaded inside the malicious WebView, to finally send them to the C2. | Version 2.25... introduced a new and interesting feature: Cookie Stealing or Cookie logger
Sharkbot lures victims to enter their credentials in windows that mimic benign credential input forms. When the user enters credentials in these windows, the compromised data is sent to a malicious server.
with the REQUEST_IGNORE_BATTERY_OPTIMIZATIONS permission, it is able to bypass Android's doze component and stay connected to the C2 servers to continue its malicious behavior
The exchange with the CnC server happens over HTTP with POST request on path / .
it uses an external module, downloaded from the C2, containing the ATS core functionalities and anti-detections technique used to slow down the static and dynamic analysis
Remote control/ATS: this feature allows Sharkbot to simulate accessibility events such as button clicks, physical button presses, TextField changes, etc.
206 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of advanced Android banking malware; also cited as having cookie stealer capabilities later mirrored by Xenomorph.
Referenced as another active mobile banking malware family in 2022.
Mentioned as another banking malware associated with ATS capabilities.
Android banking trojan distributed via Google Play droppers. The campaign targeted Italian users via fake update flows, and the payload targeted banking apps across multiple countries to steal banking-related data and enable fraud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.