Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityfinancial-sector-threatcryptocurrency-platform-riskcommand-and-control-method

Android Banking Trojan Masquerades as News and ID Apps to Steal Credentials and Crypto

Updated 3mo agoFirst seen Nov 4, 20252 sources

A sophisticated Android banking Trojan, identified as Android/BankBot-YNRK, has been discovered targeting users primarily in Indonesia and potentially other Southeast Asian countries. The malware disguises itself as legitimate applications, including news readers and digital ID apps such as "Identitas Kependudukan Digital," to trick users into installation. Once installed, it leverages Android's accessibility features and device administrator privileges to gain extensive control over the device, allowing it to read on-screen content, simulate user actions, and overlay fake login screens on top of real banking and cryptocurrency apps to harvest credentials.

The Trojan employs advanced evasion techniques, such as checking for emulators to avoid detection, obfuscating its code, and muting device notifications to operate stealthily. It connects to a remote command-and-control server to exfiltrate sensitive data, including banking credentials and cryptocurrency wallet keys, and can receive further instructions to update itself or erase traces. The malware's primary objective is financial theft, enabling attackers to drain victims' bank accounts and crypto wallets without their knowledge. Security researchers note that the malware's abuse of accessibility permissions is mitigated in Android 14, which requires explicit user approval for such access, but devices running Android 13 and earlier remain vulnerable.

Share:
Android Banking Trojan Masquerades as News and ID Apps to Steal Credentials and Crypto
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Nov 3, 20258mo ago

Android 14 protections noted as partial mitigation for accessibility abuse

Researchers highlighted that Android 14 introduces changes requiring more direct user permission for accessibility features, which can mitigate some of the attack vectors used by this malware family. The protection was described as only partial, since the campaign still primarily threatens users who sideload apps outside official app stores.

Researchers document advanced evasion and wallet-draining capabilities

Security reporting detailed that the malware automates UI interactions, captures real-time screenshots to map banking app layouts, disables audio alerts, survives reboots, and adapts to device models while using obfuscation and permission tricks to evade detection. Researchers from Cyfirma and Intel471 also noted a broader rise in sophisticated Android malware using leaked source code and specialized droppers to bypass security restrictions.

Android/BankBot-YNRK campaign targets Indonesian Android users

A new Android banking Trojan tracked as Android/BankBot-YNRK was observed actively targeting users in Indonesia, and possibly other Southeast Asian countries, by disguising itself as legitimate apps such as Indonesia's digital national ID app and fake news applications. The malware abuses Android accessibility services to take remote control of devices, intercept SMS, steal credentials and other sensitive data, and drain cryptocurrency wallets.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Malware
1 linked
Affected products
1 linked
Android
Organizations
6 linked
SamsungSamsung ElectronicsIdentitas Kependudukan DigitalIntel 471CYFIRMAGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.