Exobot is an Android banking trojan first observed in 2016 and associated with credential theft, SMS interception, and phishing overlays targeting financial applications. It has been described as one of the more active Android banking malware families of its period and is widely regarded as part of the broader Android banking trojan ecosystem alongside families such as BankBot, MazarBot, and Anubis. Exobot has also been linked historically to later descendants and rebrands including ExobotCompact and malware tracked as Coper or Octo.
The malware is designed to steal banking credentials and facilitate account takeover and fraud on infected Android devices. Reported capabilities include displaying phishing popups or overlay-style prompts when targeted applications are running, using web injects to capture user credentials, intercepting and forwarding SMS messages, accessing the victim’s contact list, and enumerating installed applications. Exobot has also been observed detecting antivirus applications and attempting to close them, indicating explicit defense-evasion behavior. For command and control, it has used HTTPS communications.
Exobot supports persistence on Android by registering for device boot events so that it can automatically activate after reboot. It has also been noted for masquerading as legitimate applications or trusted brands, including popular consumer services, to improve installation success and reduce suspicion. Across reporting, Android banking trojans of this class have commonly been distributed as trojanized or deceptive apps via unofficial channels, malicious links, and at times official app marketplaces; however, the specific delivery mechanism for Exobot itself is not established here at high confidence beyond masquerading as legitimate apps.
Historically, Exobot was offered as a malware service before its source code was sold and later leaked, a development that increased concern about derivative variants and broader criminal adoption. Security reporting has also noted that Exobot was based on Marcher code and that campaigns targeted financial institutions in multiple countries including Turkey, France, Germany, Australia, Thailand, and Japan. Its combination of overlay phishing, SMS interception, app discovery, and boot persistence made it a significant Android banking threat and an important ancestor in the evolution of later mobile banking malware families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Web injects (show phising over targeted app names to steal data, username,password,telepin whatever you want)
The keylogger functionality is a primary feature of Coper/Octo, enabling it to log every keystroke made on the victim’s phone.
Intercepting, redirecting, sending and deleting SMS messages, to bypass SMS-based 2-factor authentication
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier Android malware family from which Coper/Octo evolved; ExobotCompact is described as a lite version later updated and rebranded as Octo.
Earlier Exobot Android banking trojan family referenced as the predecessor to ExobotCompact and an ancestor in the lineage leading to Octo and likely Coper.
Earlier banking trojan family and predecessor in the lineage leading to ExobotCompact and later Octo; targeted financial institutions across multiple countries.
Referenced as the earlier Android malware lineage from which ExoBotCompat/Coper is derived.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.