Security researchers reported that leaked source code for the Android banking malware GM Bot enabled broader criminal reuse of a trojan capable of stealing banking credentials, intercepting SMS messages, and bypassing two-factor authentication. IBM said the malware—also tracked under names including Slempo, Bankosy, Acecard, and MazarBot—abused Android activity hijacking on older devices to display fake login overlays on legitimate banking apps, making the leak significant because it lowered the barrier for other actors to build or modify mobile banking trojans.
ESET later linked publicly released Android banker and command-and-control source code from a Russian forum to an active banking botnet campaign distributed through trojanized weather apps on Google Play. The newer malware, detected as Trojan.Android/Spy.Banker.HW, posed as World Weather, expanded targeting from 22 Turkish banks to 69 banking apps across Turkey, the UK, Germany, and Austria, and added stronger obfuscation while retaining SMS interception and remote lock and unlock functions. An exposed control panel showed more than 2,800 infected devices, and the hosting provider removed the C2 server after notification.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
The Trojan.Android/Spy.Banker.HW sample remained on Google Play until February 20, 2017, when it was removed after ESET reported it. The app retained legitimate weather functionality while adding credential theft, SMS interception, and remote lock/unlock features.
ESET discovered a newer Android banking trojan variant masquerading as the legitimate app World Weather on Google Play. The sample, detected as Trojan.Android/Spy.Banker.HW, expanded targeting to 69 banking apps across Turkey, the UK, Germany, and Austria.
ESET found that the malware's command-and-control server had been active since February 2, 2017. The exposed control panel was accessible without credentials and provided visibility into more than 2,800 infected devices.
ESET said Dr.Web had analyzed an earlier malware variant that ESET detected as Android/Spy.Banker.HH starting on December 26, 2016. ESET noted that this sample belonged to the same malware family but was not directly tied to the later Google Play variants.
ESET reported that Android banking malware source code and accompanying C&C server code, including a web control panel, had been publicly available on a Russian forum since December 19, 2016. ESET concluded later Google Play banking trojans were built from this released code.
IBM said the Android banking malware GM Bot first appeared on Russian-speaking forums in late 2014. The malware was designed to steal banking credentials and SMS-based authentication codes from Android devices.
After ESET notified the hosting company, the provider took down the malware's command-and-control server. ESET had previously accessed the exposed panel and observed data from more than 2,800 infected bots.
After the source code leak, IBM said the malware's creators appear to have developed and sold a second GM Bot version on underground forums focused on financial fraud. This indicated continued commercialization of the malware family despite the leak.
IBM Trusteer analyst Limor Kessem wrote that a buyer of the GM Bot code apparently reposted an encrypted archive containing the malware source code on a forum in December. The password was then shared beyond the original audience, widening distribution of the code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.