Ginp is an Android banking trojan focused on credential and payment-card theft through phishing overlays and abuse of Android accessibility features. It has been observed masquerading as legitimate applications such as Adobe Flash Player and Google Play-related software to induce installation and permission grants. After installation, it can request Accessibility Service access, enumerate installed applications, monitor when targeted apps are opened, and launch WebView-based overlay pages to capture banking credentials and card data. Ginp has also used themed social-engineering lures, including a COVID-19-related “Coronavirus Finder” fraud, to trick victims into submitting payment information.
Beyond overlay-based credential theft, Ginp supports broad device-data collection and messaging abuse. Reported capabilities include collecting SMS messages, sending SMS messages, downloading the device contact list, obtaining installed application lists, and retrieving device logs. It can use fake notifications and inserted SMS messages to drive victims into targeted applications, and it has been reported to hide or suppress SMS activity by taking over default messaging functionality. Ginp also employs defense-evasion and persistence-related behaviors such as hiding its icon, redirecting users away from settings screens, and attempting to interfere with Google Play Protect.
Ginp is widely characterized as a banking trojan targeting Android devices, with activity observed in campaigns affecting users in Europe, including Spain and Greece. Code reuse from Anubis has been reported in some Ginp development. Its operational model centers on post-installation fraud enablement: harvesting credentials, intercepting or abusing SMS for account takeover and smishing, collecting device intelligence, and exfiltrating victim data to operator-controlled infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
A malicious application could create an application overlay window on top of a running legitimate application.
we will see it is nop code and obfuscated code which makes the analysis of the code more harder and it’s an indicator that the sample is packed... the packer is JsonPacker
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan that uses Accessibility abuse and overlay attacks to steal login and credit card credentials from targeted apps. It can collect installed apps, receive C2 commands, push fake notifications, generate fake SMS messages to lure victims into opening banking apps, steal stored SMS messages and contacts, send smishing SMS, hide incoming SMS by becoming the default messaging app, take screenshots, disable Play Protect, and maintain persistence by hiding its icon and interfering with user actions.
Android banking trojan that disguises itself as Adobe Flash Player or Google Play verification software.
Android banking trojan that uses multi-step phishing overlays to steal banking credentials and payment card data.
Android banking trojan that enumerates installed applications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.