FluBot emerged as a large Android banking malware operation that spread through smishing messages impersonating parcel delivery, voicemail, WhatsApp, and security-update themes, luring users to install malicious APKs from fake or hacked websites. Researchers reported that the malware abused Android Accessibility Services and SMS privileges to disable protections, steal banking credentials and card data through overlays, intercept verification codes, harvest contacts, and self-propagate by sending large volumes of text messages; Deutsche Telekom said infected devices sent about 1,000 SMS per day on average, with some reaching 3,000. Analysis from multiple firms also found encrypted or obfuscated payloads, DGA-based infrastructure discovery, rotating domains, and evolving command-and-control techniques, while some campaigns additionally delivered other malware families including TeaBot and Medusa.
The campaign heavily affected Spain and later expanded across Europe and beyond, with reports linking it to at least 60,000 infected devices, roughly 11 million harvested phone numbers, and tens of thousands of spam SMS messages. Catalan police arrested four suspects in Barcelona tied to the operation, including an alleged malware author, but FluBot activity continued after those arrests and kept evolving through new variants such as voicemail-themed samples and country-specific campaigns. A broader international law-enforcement effort later disrupted the botnet’s infrastructure, with Europol announcing a coordinated takedown after action led in part by Dutch authorities, although researchers warned the operators could attempt to rebuild using new domains and servers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
30 events from the most recent confirmed update back to the earliest known activity.
F5 Labs reported that FluBot version 5.0 shifted command-and-control traffic from direct HTTPS/HTTP patterns to DNS tunneling over HTTPS via public resolvers. The report also said version 5.2 added an UPDATE_ALT_SEED command for remotely changing the DGA seed and expanded generated top-level domains from 3 to 30.
Europol announced that a joint operation involving 11 countries had taken down FluBot infrastructure, with Dutch police playing a central role.
Switzerland's NCSC reported that a new FluBot SMS campaign impersonating parcel delivery notifications had been active in Switzerland since 18 March 2022. The messages lured Android users to install fake courier apps that were actually FluBot malware.
Bitsight reported that in January 2022 about 170,000 IP addresses used by FluBot-infected Android devices contacted its sinkhole infrastructure. The company said FluBot activity was most prevalent in Germany and Spain, with most observed infections still running version 4.8 or earlier.
Fox-IT reported that FluBot introduced a Flash Player-themed campaign in December 2021 to trick users into installing a fake app to watch a purported video.
Fox-IT reported that FluBot introduced a fake Android Security Update campaign in October 2021.
As of September 2021, Telekom Security observed FluBot campaigns distributing both FluBot and TeaBot payloads.
Telekom Security observed FluBot campaign themes moving from voicemail lures to parcel-service and DHL-themed lures in late August and September 2021.
Telekom Security reported renewed FluBot activity by September 2021 after the earlier summer decline.
A SWITCH security blog post documented FluBot activity reaching Switzerland, marking the malware's presence in the country during 2021. The report indicates Swiss users were being targeted as the Android banking malware continued expanding across Europe.
Fox-IT reported that FluBot introduced a VoiceMail-themed smishing campaign in June 2021 to lure victims into installing a fake voicemail app.
Telekom Security observed a decline in detected FluBot infections among Deutsche Telekom customers during June and July 2021.
ThreatFabric observed a new Netherlands smishing campaign masquerading as UPS apps that delivered both Cabassous/FluBot and Anatsa from the same malicious links.
Germany's BSI and the UK's NCSC warned of a spike in FluBot SMS spam campaigns impersonating parcel delivery services such as DHL and FedEx. The report said FluBot activity had expanded beyond Spain, Germany, and the UK to additional countries across Europe and Japan.
ThreatFabric reported that Cabassous began using multiple DGA seeds in every sample to improve scalability.
A second update on the same day noted that FluBot version 3.8 was already being distributed.
An update to the Cryptax analysis stated that a new FluBot campaign in Hungary had been confirmed.
Cryptax reported that FluBot version 3.7 started propagating, with the campaign still aimed at German-speaking users despite code preparation for Hungary.
The four Barcelona suspects were brought before a judge, with two alleged leaders detained and two others released under court reporting requirements.
Catalan police arrested four men in Barcelona on suspicion of distributing FluBot during raids that seized cash, laptops, documents, and mobile devices.
PRODAFT said FluBot had infected about 60,000 devices and harvested more than 11 million phone numbers, mostly belonging to Spanish citizens.
Fox-IT states that ThreatFabric first published public information about the malware on January 6, 2021, referring to it as Cabassous.
Telekom Security said it detected thousands of FluBot infections affecting Deutsche Telekom customers during 2021 and observed infected devices sending around 1,000 SMS per day on average.
ThreatFabric discovered the Android banking trojan Anatsa in January 2021, later observing it in campaigns alongside Cabassous/FluBot.
Fox-IT reported that between versions 0.1 and 0.5, FluBot introduced web injections to steal credentials from targeted banking users.
ThreatFabric discovered the Android malware later known as FluBot, which it initially called Cabassous, in early December 2020.
Multiple references state that FluBot emerged in late 2020 as an Android banking malware and smishing botnet targeting mobile users.
ThreatFabric reported Medusa samples observed alongside Cabassous/FluBot were tagged FLUVOICE, FLUFLASH, and FLUDHL, suggesting overlap with corresponding FluBot campaign themes.
Cyble Research Labs analyzed a FluBot sample masquerading as a Voicemail app that abused accessibility, notification access, and default SMS privileges, and published related IOCs.
NVISO analyzed a repackaged WhatsApp-based FluBot sample targeting Spanish banking and cryptocurrency apps and captured plaintext C2 commands and overlay delivery behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
blog.fox-it.com
Open sourcef5.com
Open sourceeuropol.europa.eu
Open sourcencsc.admin.ch
Open sourcetherecord.media
Open sourceprodaft.com
Open sourcesecurityblog.switch.ch
Open sourcecleafy.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.