Skip to main content
Mallory
MalwareUsed by 1 actor

Klopatra

Klopatra is an Android banking trojan and remote access trojan (RAT) first observed in March 2025. It is described as a previously undocumented malware family with no confirmed links to known Android malware families, and reporting ties its operation to a Turkish-speaking cybercrime group. The malware has infected more than 3,000 devices, with the majority of reported infections in Spain and Italy, and broader targeting across Europe.

Klopatra is distributed outside Google Play via social-engineering lures, particularly a dropper disguised as an IPTV/VPN application named "Modpro IP TV + VPN." Victims are prompted to allow installation from unknown sources, after which the dropper installs the main payload. The malware abuses Android Accessibility Services to gain permissions, monitor the screen, capture user input, simulate taps and gestures, and automate actions on the victim device.

Its capabilities support both credential theft and full device takeover for banking fraud. Reported functions include dynamic overlay attacks against banking and cryptocurrency applications, screen monitoring, keystroke and clipboard exfiltration, gesture simulation, and hidden VNC/black-screen VNC remote control. The VNC capability allows operators to interact with the device while it appears locked, idle, or dark to the victim, enabling manual fraudulent transactions such as draining bank accounts. Operators reportedly check conditions such as whether the device is charging, the screen is off, or the device is idle before activating the black-screen mode. Klopatra also collects information related to cryptocurrency wallet applications.

Klopatra includes multiple stealth and anti-analysis features. Reported protections include Virbox commercial code protection, heavy use of native libraries, string encryption, anti-debugging, runtime integrity checks, and emulator detection. It also contains a hardcoded list of Android antivirus package names and attempts to uninstall targeted security products to evade detection.

Researchers reported roughly 40 distinct Klopatra builds within a few months, indicating rapid active development. Infrastructure analysis linked multiple command-and-control points to at least two campaigns, and shared infrastructure has also been noted with other Android malware families including Medusa and Perseus. High-confidence infection themes and indicators mentioned in the content include the "Modpro IP TV + VPN" lure, targeting of banking and cryptocurrency apps, abuse of Accessibility permissions, hidden/black-screen VNC functionality, and concentration of infections in Spain and Italy.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Turkish-speaking criminal group

A previously undocumented Android banking trojan called Klopatra has compromised over 3,000 devices, with a majority of the infections reported in Spain and Italy.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

18 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1648Serverless ExecutionEvidence1

“Klopatra abuses Android’s Accessibility service to grant itself additional permissions, capture user inputs, simulate taps and gestures, and monitor the victim’s screen…”

Privilege Escalation

2 techniques
T1055.011Extra Window Memory InjectionEvidence1

Capabilities may include overlay attacks on banking apps... These features allow attackers to conduct unauthorized transactions with minimal user awareness.

T1548Abuse Elevation Control MechanismEvidence1

Once installed, the malware leverages advanced techniques such as overlay attacks, SMS interceptions, keylogging, and abuse of Android Accessibility Services to harvest credentials in real time.

Stealth

5 techniques
T1027Obfuscated Files or InformationEvidence3

Stealth tactics: Virbox code protection, anti-debugging, emulator detection, AV app uninstall attempts.

T1036MasqueradingEvidence1

Disguised as an IPTV + VPN app (“Modpro IP TV + VPN”) outside Google Play.

T1055.011Extra Window Memory InjectionEvidence1

Capabilities may include overlay attacks on banking apps... These features allow attackers to conduct unauthorized transactions with minimal user awareness.

T1497Virtualization/Sandbox EvasionEvidence2

Stealth tactics: Virbox code protection, anti-debugging, emulator detection, AV app uninstall attempts.

T1622Debugger EvasionEvidence1

Stealth tactics: Virbox code protection, anti-debugging, emulator detection, AV app uninstall attempts.

Credential Access

4 techniques
T1056Input CaptureEvidence2

Capabilities include screen monitoring, overlay attacks for credential theft, gesture simulation, and clipboard/keystroke exfiltration.

T1056.001KeyloggingEvidence2

Capabilities include screen monitoring, overlay attacks for credential theft, gesture simulation, and clipboard/keystroke exfiltration.

T1056.003Web Portal CaptureEvidence2

Capabilities include screen monitoring, overlay attacks for credential theft, gesture simulation, and clipboard/keystroke exfiltration.

T1555Credentials from Password StoresEvidence1

These malware families are specifically designed to steal credentials related to banking platforms, financial services, and cryptocurrency exchanges.

Discovery

2 techniques
T1497Virtualization/Sandbox EvasionEvidence2

Stealth tactics: Virbox code protection, anti-debugging, emulator detection, AV app uninstall attempts.

T1622Debugger EvasionEvidence1

Stealth tactics: Virbox code protection, anti-debugging, emulator detection, AV app uninstall attempts.

Lateral Movement

1 technique
T1021.005VNCEvidence1

Features a hidden black-screen VNC mode — attackers drain accounts while the device looks locked/idle.

Collection

5 techniques
T1056Input CaptureEvidence2

Capabilities include screen monitoring, overlay attacks for credential theft, gesture simulation, and clipboard/keystroke exfiltration.

T1056.001KeyloggingEvidence2

Capabilities include screen monitoring, overlay attacks for credential theft, gesture simulation, and clipboard/keystroke exfiltration.

T1056.003Web Portal CaptureEvidence2

Capabilities include screen monitoring, overlay attacks for credential theft, gesture simulation, and clipboard/keystroke exfiltration.

T1113Screen CaptureEvidence3

For surveillance, Rokarolla skips the usual MediaProjection screen casting ... and instead takes screenshots through Accessibility, compresses them to PNG, and ships them out one frame at a time.

T1115Clipboard DataEvidence1

“…exfiltrate clipboard content and keystrokes…”

Command and Control

2 techniques
T1071.001Web ProtocolsEvidence1

“Although the operators of the malware use Cloudflare to hide their digital tracks…”

T1219Remote Access ToolsEvidence1

Klopatra functions both as a Remote Access Trojan (RAT) and an Android Banking Trojan.

Other

2 techniques
T1562Impair DefensesEvidence1

Stealth tactics: Virbox code protection, anti-debugging, emulator detection, AV app uninstall attempts.

T1562.001Disable or Modify ToolsEvidence1

“…contains a hardcoded list of package names corresponding to popular Android antivirus products, and attempts to uninstall them.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping18

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.