SharkBot is an Android banking trojan discovered in October 2021 that steals banking credentials, financial information, and session cookies and supports automated fraudulent transactions on infected devices. Its targeting has included banking applications in Italy, the United Kingdom, Germany, Spain, Poland, Austria, the United States, and Australia.
SharkBot abuses Android Accessibility Services to identify foreground applications, observe interface events, capture keystrokes and text changes, and simulate user actions. It presents fraudulent login overlays when targeted banking applications open and uses an Automated Transfer System (ATS) to automate financial transactions. Some configurations force password-based login instead of fingerprint authentication to facilitate credential capture. The malware can intercept, hide, and send SMS messages, change the default SMS handler, collect contacts, and exfiltrate credentials and event logs. Version 2.25 introduced theft of banking session cookies through an attacker-controlled WebView after victims authenticate.
Distribution has relied on malicious Google Play dropper applications masquerading as antivirus products, cleaners, file managers, and tax-code utilities. These applications retrieve the banking payload and induce victims to install it as an update, sometimes through a counterfeit Google Play page opened in a browser. Earlier droppers used accessibility permissions to automate installation. Campaigns selectively deliver payloads according to device country and installed banking applications.
SharkBot hides its application icon, bypasses battery optimization to sustain background activity, and employs obfuscation, sandbox detection, and geographic filtering. It supports downloading additional executable modules, including ATS functionality. Command-and-control communication uses encrypted HTTP requests, with a fallback domain generation algorithm when configured servers are unavailable.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
the very first samples tracked down at the end of October use: a demo version of the Allatori Java Obfuscation
SharkBot hides itself with common names and icons posing as a legitimate application to the victims
removeApp ... the server sends a huge list of applications which should be uninstalled from the user’s device.
Sharkbot lures victims to enter their credentials in windows that mimic benign credential input forms. When the user enters credentials in these windows, the compromised data is sent to a malicious server.
Keylogging: this feature allows Sharkbot to receive every accessibility event produced in the infected device, this way, it can log events such as button clicks, changes in TextFields
SharkBot is able to read/send text messages, perform overlay attacks
CherryBlos has exfiltrated credentials collected from pictures that have been analyzed using optical character recognition (OCR).
Once the victim logged in to his bank account, the malware will receive the PageFinished event and will get the cookies of the website loaded inside the malicious WebView, to finally send them to the C2. | Version 2.25... introduced a new and interesting feature: Cookie Stealing or Cookie logger
Sharkbot lures victims to enter their credentials in windows that mimic benign credential input forms. When the user enters credentials in these windows, the compromised data is sent to a malicious server.
with the REQUEST_IGNORE_BATTERY_OPTIMIZATIONS permission, it is able to bypass Android's doze component and stay connected to the C2 servers to continue its malicious behavior
The exchange with the CnC server happens over HTTP with POST request on path / .
it uses an external module, downloaded from the C2, containing the ATS core functionalities and anti-detections technique used to slow down the static and dynamic analysis
Remote control/ATS: this feature allows Sharkbot to simulate accessibility events such as button clicks, physical button presses, TextField changes, etc.
206 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an Android malware family that weaponizes accessibility services. The article does not describe its individual behavior.
Mentioned in passing as another banking Trojan.
Mentioned as an example of advanced Android banking malware; also cited as having cookie stealer capabilities later mirrored by Xenomorph.
Referenced as another active mobile banking malware family in 2022.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.