Aberebot is an Android banking trojan that masquerades as a legitimate mobile application, including fake Chrome-themed variants, to steal sensitive information from infected devices. It targets customers of more than 140 financial institutions across at least 18 countries and also impersonates non-banking services such as payment, email, and cryptocurrency platforms. The malware is designed for credential harvesting and financial fraud, using phishing overlays and counterfeit web content tailored to the victim’s geography.
After installation, Aberebot requests extensive Android permissions, including SMS, contacts, and accessibility-related privileges. It abuses Accessibility Service to monitor on-screen activity, enable additional permissions, interfere with user attempts to change settings, and trigger phishing overlays when targeted applications are opened. It can hide its icon after launch to reduce visibility.
Aberebot steals credentials through embedded phishing pages displayed in WebView components, intercepts SMS messages and one-time passwords, collects contact lists, enumerates installed applications, and can send SMS messages under operator control. Stolen data is exfiltrated through Telegram-based command-and-control infrastructure, and the malware has also used externally hosted phishing content repositories to retrieve fraudulent pages. Samples have been observed using obfuscation, encrypted strings, and AES-based decryption routines to hinder analysis and detection.
Aberebot emerged during a broader rise in mobile malware targeting financial services and is associated with ongoing development activity, indicating continued refinement of its banking fraud and data theft capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET Stubs: Sowing the Seeds of Discord (PureCrypter) Aberebot AbstractEmu AdoBot 404 Keylogger Agent Tesla Amadey AsyncRAT Ave Maria BitRAT BluStealer Formbook LimeRAT Loki Password Stealer (PWS) Nanocore RAT Orcus RAT Quasar RAT Raccoon RedLine Stealer WhisperGate
Named as a notable example of malware targeting financial services/mobile banking during the pandemic.
Referenced as a similar Android banking trojan, particularly regarding planned Telegram-based C2 behavior.
Android banking trojan that masquerades as Google Chrome, steals contacts, OTPs, SMS data, installed app lists, and credentials for banking, social media, Gmail, PayPal, crypto and wallet apps. It uses phishing pages hosted on GitHub, displays them via WebView based on geolocation and targeted apps, abuses Accessibility Service permissions, and communicates with operators through Telegram bot C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.