GM Bot is an Android banking trojan associated with the mobile financial-malware ecosystem that expanded rapidly in the mid-2010s. It has also been referred to under several overlapping names, including Slempo, Bankosy, and Acecard. The malware emerged on Russian-speaking underground forums and was sold to other criminals, after which its source code was leaked more broadly, lowering the barrier to entry for additional threat actors and likely contributing to derivative variants and wider reuse.
GM Bot is designed primarily to steal online banking credentials from Android users. Its core tradecraft includes abusing Android activity hijacking on older devices to place convincing overlay screens on top of legitimate banking applications, tricking victims into entering credentials into attacker-controlled forms while the real application remains active underneath. It also steals SMS messages, including one-time authentication codes, enabling attackers to bypass SMS-based two-factor authentication and facilitate fraudulent banking access. Reporting also indicates that it can obtain extensive control over infected Android devices.
GM Bot has been discussed alongside other active Android banking trojans such as Exobot, BankBot, Marcher, Mazar Bot, and Red Alert, reflecting its place in a broader criminal ecosystem focused on mobile banking fraud. Android banking trojans in this ecosystem have been used in schemes involving online banking theft, fake mobile-banking interfaces, interception of banking access, and automated fraud workflows. GM Bot is notable because the leak of its source code increased the likelihood of repackaging, modification, and proliferation by lower-skilled operators, amplifying the mobile banking threat landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
It exploits an issue known as activity hijacking in older Android devices that allow an overlay to be displayed over a legitimate application. The overlay looks like what a user would expect to see after launching a legitimate banking app, but that app is actually running underneath the overlay. The user then inputs their authentication credentials, which are sent to the attackers.
It exploits an issue known as activity hijacking in older Android devices that allow an overlay to be displayed over a legitimate application. The overlay looks like what a user would expect to see after launching a legitimate banking app, but that app is actually running underneath the overlay. The user then inputs their authentication credentials, which are sent to the attackers.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan listed in the expanding Android trojan market.
Android banking trojan mentioned for comparison and as another family whose code was leaked and remixed into offshoots.
Android banking trojan whose leaked source code enables theft of online banking credentials by abusing activity hijacking/overlay attacks on older Android devices; it can also steal SMS messages including one-time authentication codes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.