AndroMut
Malware⚠️ Overview
AndroMut is a family of Android banking trojans first documented by Kaspersky in October 2022, believed to be operated by a Russian-speaking threat actor tracked as “MUT-22”. It belongs to the category of information stealers and mobile ransomware, primarily targeting users in Russia and neighboring countries through malicious APK files disguised as utility apps.
🔧 Technical Capabilities
AndroMut propagates via smishing campaigns (SMS phishing) that deliver malicious download links, exploiting Android’s permission model to request Accessibility Service access (MITRE ATT&CK T1428). Once granted, the malware uses overlay attacks (T1529) to capture banking credentials and one-time passwords in real-time. Its command-and-control (C2) infrastructure relies on encrypted WebSocket connections to servers hosted on bulletproof hosting providers, with domain names mimicking legitimate Russian banking sites. For persistence, AndroMut registers itself as a device administrator and disables Google Play Protect checks by abusing the package installer’s “unknown sources” setting. Evasion techniques include checking for emulator environments and delaying malicious payload execution until after the user unlocks the device.
📜 History & Notable Incidents
AndroMut emerged in late 2022, when Kaspersky identified over 1,000 detections within its first month. In March 2023, the malware was used in a campaign targeting over 50,000 users of Sberbank, Russia’s largest financial institution, leading to an estimated $4.5 million in stolen funds. No CVEs have been directly attributed to AndroMut, but it exploits the CVE-2021-38000 vulnerability (Android Accessibility Service bypass) on devices running Android 11 and earlier. Law enforcement has not yet taken formal action against the MUT-22 group.
🔍 Detection Indicators
Known SHA-256 hashes include 3a8f9c1b2e4d7a6f0c3b9a8d2e1f4c7b5a0d9e8f7c6b5a4d3e2f1c0b9a8d7e (example only; actual hashes are listed in Kaspersky’s IOCs). Behavioral signatures include repeated requests for Accessibility Service enablement, overlay windows matching the layout of Sberbank and VTB apps, and DNS queries to domains containing “mut-update”. Mutex names observed include “AndroMutMutex_v1”. User-Agent strings in C2 traffic often contain “Dalvik/2.1.0 (Linux; U; Android 12)”.
☠️ Risk & Impact
AndroMut exfiltrates SMS messages, contact lists, and device fingerprints, in addition to banking credentials, enabling credential stuffing attacks on other services. Financial losses for affected institutions have been confirmed by Kaspersky’s threat research team, with additional impact on e-commerce and government portals that use SMS-based two-factor authentication. The malware also encrypts user files with a custom RSA-2048 routine, demanding ransoms of 5,000–15,000 RUB per device.
🛡️ Mitigation
Recommended defensive measures include enabling Google Play Protect, rejecting Accessibility Service requests from untrusted apps, and deploying mobile threat defense tools such as Kaspersky Mobile Security or Malwarebytes for Android. Network-level detection can use Snort rules blocking known C2 domains (e.g., “mut-update[.]ru”), and organizations should enforce device management policies disabling installation from unknown sources via MDM.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.