Xbot is an Android banking trojan and mobile malware family that combines credential phishing, SMS theft, contact harvesting, device locking, and rudimentary ransomware behavior. It has been observed masquerading as legitimate Android applications and using phishing pages that imitate Google Play payment prompts and bank login interfaces to steal payment card data, banking credentials, and related authentication information. The malware can monitor the foreground application and present deceptive overlays or WebView-based phishing content, enabling theft of credentials from targeted financial and payment applications.
Xbot is also capable of stealing all SMS messages and contact data, intercepting and parsing selected SMS messages for banking-related authentication content, and uploading stolen information to command-and-control infrastructure. Additional observed functionality includes sending SMS messages, including premium-rate SMS in some variants, hiding its launcher icon for stealth, persisting across device reboot, downloading and executing additional APK payloads, and receiving remote commands that control phishing and post-compromise actions.
Some Xbot variants abuse device administrator privileges to lock the device, reset the device password, and display a ransom screen. The family has also been documented encrypting files on external storage and demanding payment from victims, although the encryption implementation observed in early reporting was comparatively unsophisticated. Xbot has been described as under active development, with evolving obfuscation and anti-analysis measures including use of DexGuard in later versions. It has been assessed as a successor to the earlier Android trojan Aulrin based on similarities in structure and behavior.
Targeting has included users in Russia, Eastern Europe, and Australia, with particular emphasis on banking fraud and theft of payment information. Distribution has been observed through malicious Android applications and third-party or local app markets rather than exclusively through official channels. Overall, Xbot is best characterized as an Android banking trojan with infostealing, phishing, and limited ransomware capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
As a part of anti-analysis protection, the author(s) try to obfuscate these samples to make them harder to read.
The communication with the C&C server uses URL parameters to send the data and a php script to process them.
After being installed on an Android device, Xbot will start communicating with its C2 server. When certain commands are received it will launch phishing attacks...
It can also remotely lock infected Android devices, encrypt the user’s files in external storage (e.g., SD card), and then ask for a U.S. $100 PayPal cash card as ransom.
Then, if the C2 server sends the command “killon”, it will change the phone to silent mode, reset the password to “1811blabla”, then toggle the device screen to activate the new password. | Xbot will also start the onBackPressed(), onDestroy() and onPause() callback methods to prevent the user from exiting.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan listed among malware targeting Europe and the USA.
Android trojan that mimics Google Play payment and bank login pages to steal financial credentials.
Android banking trojan that steals SMS messages and contacts and intercepts/parses selected SMS traffic.
Android malware that steals SMS messages and contacts, and intercepts and parses selected SMS traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.