Octo is an Android banking trojan and malware-as-a-service offering widely assessed as a rebranded evolution of ExobotCompact, part of the broader Exobot lineage first seen in 2016. It is designed for on-device fraud by giving operators remote control over infected phones and by harvesting credentials and other sensitive data from banking and financial applications. Octo has been used in campaigns targeting users across Europe and other regions, including the United States, Canada, the Middle East, Singapore, and Australia, with particular focus on financial institutions and related services.
On infected devices, Octo abuses Android Accessibility Services and the MediaProjection API to observe screen contents and perform remote actions. Operators can stream the victim’s screen, read interface elements, simulate taps and gestures, enter text, manipulate the clipboard, scroll through applications, launch apps or URLs, and otherwise interact with the device as though physically present. To conceal fraudulent activity, Octo can display a black screen overlay, reduce screen brightness to zero, mute or suppress notifications, and block push notifications from selected applications. These capabilities enable covert takeover of banking sessions and other sensitive workflows directly from the victim device.
Octo also supports credential theft and broader surveillance functions. Reported capabilities include keylogging through accessibility-event capture, overlay attacks against banking apps, SMS interception, harvesting of contacts and installed application data, and collection of information displayed by arbitrary apps. Its command set has included remote-session control, SMS sending, app launching, URL opening, app minimization, USSD execution, and command-and-control server updates. Some variants have used native-code payload decryption and obfuscation to hinder reverse engineering and signature-based detection, and later Octo2 samples added stronger obfuscation, dynamic native-library loading, per-request encryption keys, and a date-based domain generation mechanism for command-and-control discovery.
Distribution has relied heavily on malicious Android applications masquerading as legitimate software, including utility, security, browser, and update-themed lures. Observed delivery channels include rogue apps on Google Play, fraudulent landing pages, fake browser or Play Store update prompts, and droppers such as GymDrop, DawDropper, and Zombinder. In some campaigns, first-stage installers were used to bypass newer Android installation restrictions before deploying the Octo payload.
Octo has been associated with an operator using the aliases Architect and goodluck, and multiple threat actors have reportedly rented or deployed it. The 2024 leak of Octo source code led to forks and the emergence of Octo2, a successor variant intended to improve remote-session stability and operational resilience. Octo remains a significant Android banking threat because its device-takeover model places not only banking apps but also authenticator, messaging, and other high-value applications at risk.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new Android banking malware named Octo has appeared in the wild, featuring remote access capabilities that allow malicious operators to perform on-device fraud.
A new Android banking malware named Octo has appeared in the wild, featuring remote access capabilities that allow malicious operators to perform on-device fraud.
The mobile threat landscape has been shaped over the years by well-established banking Trojan families such as Anatsa, Octo, Hook...
28 distinct techniques documented for this family, organized by ATT&CK tactic.
These apps, which pose as Play Store app installer, screen recording, and financial apps, are "powered by inventive distribution schemes," distributing them through the Google Play store and via fraudulent landing pages that purportedly alert users to download a browser update.
Once the Octo malware is successfully launched in the victim’s device and gains primary permissions, it will keep the device awake and register a scheduled service to collect and upload sensitive data to its C&C server.
Once the Octo malware is successfully launched in the victim’s device and gains primary permissions, it will keep the device awake and register a scheduled service to collect and upload sensitive data to its C&C server.
Once the Octo malware is successfully launched in the victim’s device and gains primary permissions, it will keep the device awake and register a scheduled service to collect and upload sensitive data to its C&C server.
The droppers, once installed, act as a conduit to launch the trojans, but not before requesting users to enable the Accessibility Services that allow it a wide breadth of capabilities to exfiltrate sensitive information from the compromised phones.
The remote access is provided through a live screen streaming module (updated every second) through Android's MediaProjection and remote actions through the Accessibility Service.
Accessibility Index: Displays instructions on how to enable Accessibility Services, which are required to be activated in order to facilitate remote interactions with the infected device. A degree of social engineering is employed to encourage the victim to take this action
Octo2 contains sophisticated obfuscation techniques to ensure the Trojan stays undetected... In Octo2, the developers implemented an even more sophisticated process of malicious code obfuscation... including decrypting and dynamically loading an additional native library, which is responsible for decrypting the malicious payload.
To evade detection, all Dex classes associated with Coper/Octo are encrypted using a hardcoded RC4 key
Another actor behind ExobotCompact.D seems to be highly focused on customers of several European banks and is using their icons and application names to lure victims into installing the application.
Other notable features of Octo include... carrying out overlay attacks on banking apps to capture credentials...
URL Inject: Displays an overlay web page, such as an authentication form, when the victim user accesses an app. The URL inject allows for the harvesting of credentials from any accounts or applications the operator wishes to target.
When a victim device is initially registered with the bot C2 server, essential information such as the IMEI number, phone model, Android version, device uptime, etc., is collected and stored in an SQL database.
Other notable features of Octo include... persistence measures to prevent uninstallation and evade antivirus engines.
The malware can also disable Google Play Protect ... and collects user data, including an infected mobile phone’s Android ID, contact list, installed apps, and even text messages.
Other notable features of Octo include... carrying out overlay attacks on banking apps to capture credentials...
URL Inject: Displays an overlay web page, such as an authentication form, when the victim user accesses an app. The URL inject allows for the harvesting of credentials from any accounts or applications the operator wishes to target.
DawDropper uses Firebase Realtime Database, a third-party cloud service, to evade detection and dynamically obtain a payload download address. It also hosts malicious payloads on GitHub.
Most of the changes are focused on increasing the stability of remote control sessions while performing Device Takeover attacks... The developers of Octo2 updated the RAT capabilities of the malware to increase the stability and decrease connection latency during remote sessions.
120 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only in related content as an Android banking trojan/rebrand of ExobotCompact.
Mentioned only as a well-known malware variant found alongside the newly observed samples on shared distribution infrastructure.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Referenced as an established mobile banking trojan family; the content also notes the threat actor sybra used Octo mobile malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.