Vultur is an Android banking trojan identified in 2021 that combines credential theft with remote-control capabilities to facilitate fraud directly on infected devices. It targets banking and cryptocurrency applications and also captures input from selected messaging and social-media applications. Campaigns have targeted users in Australia, Italy, Spain, the United States, the United Kingdom, the Netherlands, Germany, and France.
Vultur monitors foreground applications and uses screen recording, VNC-based screen streaming, and Android Accessibility Services to collect credentials and personally identifiable information. Its accessibility-based keylogging captures interface text and events, supplementing screen capture when Android FLAG_SECURE protections obscure sensitive application windows. Remote sessions and backend-scripted command sequences enable attackers to interact with financial applications and perform on-device fraud. Updated variants support accessibility-driven clicks, swipes, scrolling, audio controls, file upload and download, file deletion, software installation, application blocking, custom notifications, and disabling Keyguard to weaken lock-screen protections.
Distribution is closely associated with the Brunhilda dropper framework and the Brunhilda Project crew. Google Play campaigns have used functional-looking authenticator and file-recovery applications that prompt victims to install purported updates containing Vultur. Other campaigns combine SMS warnings about unauthorized transactions with fraudulent phone calls directing victims to install a trojanized security application.
Vultur uses Firebase Cloud Messaging for command delivery, alongside HTTPS command-and-control communications. Updated variants encrypt communications with AES and encode them with Base64. Staged payloads, native-code payload decryption, and impersonation of legitimate security and accessibility software complicate analysis and conceal malicious functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
First discovered by ThreatFabric in July 2021, Vultur is an Android banking trojan which specializes in stealing PII from infected devices using its screen-streaming capabilities.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
With Vultur fraud can happen on the infected device of the victim. These attacks are scalable and automated ... circumventing detection based on phishing MO’s that require fraud to be performed from a new device
In order to deceive unsuspecting individuals into installing malware, the threat actors employ a hybrid attack using two SMS messages and a phone call. First, the victim receives an SMS message that instructs them to call a number if they did not authorise a transaction involving a large amount of money... A second SMS is sent during the phone call, where the victim is instructed into installing a trojanised version of the McAfee Security app from a link.
These attacks are scalable and automated since the actions to perform fraud can be scripted on the malware backend and sent in the form of sequenced commands.
Brunhilda and Vultur have started using native code for decryption of payloads, likely in order to make the samples harder to reverse engineer.
Sideloading bypasses the official app stores’ rigorous vetting processes... [It leaves] devices exposed to malware and unauthorized code.
The latest version of Brunhilda also implemented a new layer of obfuscation, which encrypts strings by using AES with a varying key
in these new version, the installation logic is not contained in the main DEX file, but in a additional dex file which is loaded dynamically.
the dropper initially sends a registration message to its C2 server. As a response, the server sends back an appToken, which is then used in the following requests to identify the device.
Otherwise, it will receive a configuration data with the URL containing the payload.
nstart_vnc() libavnc.so public static void startVnc ( FileDescriptor fileDescriptor , VncSessionConfig config ... C2Commands . log ( "VNC: START VNC SERVICE" )
Threat Actors are known for monitoring public reports and adjusting infrastructure that believe may be compromised... the developers behind the Vultur banking trojan appear to have updated the naming scheme of their domain infrastructure in response to a public threat intelligence report.
Below we can see that several of the domains have historically resolved to the same IP address of 82.221.136[.]47... there are malicious domains routing through it.
Threat Actors are known for monitoring public reports and adjusting infrastructure that believe may be compromised... the developers behind the Vultur banking trojan appear to have updated the naming scheme of their domain infrastructure in response to a public threat intelligence report.
114 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an Android malware family that weaponizes accessibility services. No family-specific capabilities or campaign details are provided.
Referenced as a comparison point for mobile malware with permissions enabling remote interaction, screen capture, accessibility abuse, and interaction with finance apps.
Referenced as a comparison for permissions enabling screen capture and accessibility-service access, including interaction with financial applications. The content does not associate it operationally with AbstractEmu.
A newly identified mobile malware family mentioned in the report as part of the rise in mobile Trojan activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.