The BlackRock Android banking trojan was distributed through a fake Clubhouse website that mimicked the legitimate service and lured users seeking an Android version of the app. Instead of sending victims to Google Play, the site delivered a malicious APK from an insecure .mobi domain over HTTP. Once installed, the malware sought Accessibility Service permissions, hid its icon, contacted a command-and-control server, and used overlay attacks to steal usernames, passwords, and payment card data.
Researchers linked BlackRock to the Xerxes malware, a descendant of the LokiBot family, and found that it had expanded far beyond traditional banking targets. The trojan was reported targeting 337 apps in one analysis and 458 apps in a later campaign, spanning banking, cryptocurrency, shopping, email, social media, communication, and dating services. It also supported SMS theft, notification theft, keylogging, anti-removal behavior, and abuse of Android work profiles to gain elevated privileges, allowing attackers to bypass or weaken SMS-based two-factor authentication and broaden credential theft across consumer and enterprise use cases.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
ESET said the BlackRock sample used in the fake Clubhouse campaign could steal credentials from 458 targeted apps through overlay attacks and intercept SMS messages. It also requested accessibility-service permissions that could give attackers extensive control over infected devices.
ESET identified a campaign that used a fake Clubhouse website to distribute BlackRock to Android users while no official Android version of Clubhouse was available. The site mimicked the legitimate service, used a .mobi domain over HTTP, and directly downloaded a malicious APK.
ThreatFabric analyzed BlackRock's capabilities, including overlay attacks, SMS and notification theft, keylogging, anti-removal behavior, and abuse of Android work profiles to gain admin privileges. It reported that the malware targeted 337 applications across banking, cryptocurrency, shopping, email, social, communication, and dating categories.
ThreatFabric uncovered a new Android banking malware strain named BlackRock in May 2020. It described BlackRock as derived from Xerxes and, at that time, the only observed Android banking trojan based on Xerxes source code.
ThreatFabric said Xerxes first appeared in May 2019 as a Parasite-based trojan. BlackRock was later identified as being derived from Xerxes source code.
ThreatFabric reported that the author of the Xerxes banking malware made its source code public around May 2019. That code base was later used to derive BlackRock.
ThreatFabric said Parasite appeared in the second half of 2018 as a direct successor to MysteryBot. This placed it in the malware lineage that later led to Xerxes and BlackRock.
ThreatFabric reported that MysteryBot was active in the first half of 2018 as a LokiBot-based variant. It included upgrades to support newer Android versions.
ThreatFabric said the LokiBot Android banking trojan lineage was first observed between late 2016 and early 2017 as rented malware. BlackRock was later described as descending from this family through multiple successor strains.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.