Antidot
Malware⚠️ Overview
Antidot is a sophisticated Android banking trojan first identified in mid-2024 by threat intelligence firm Cyble, operated by an unknown threat actor group; it belongs to the Remote Access Trojan (RAT) and information stealer category, targeting banking credentials, cryptocurrency wallets, and two-factor authentication codes primarily through malicious mobile applications.
🔧 Technical Capabilities
Antidot propagates via social engineering campaigns that trick users into sideloading malicious APKs from phishing websites or SMS messages, often masquerading as legitimate apps such as Google Chrome, WhatsApp, or security updates. Once installed, it abuses Android Accessibility services to capture on-screen credentials, intercept SMS messages, and perform overlay attacks mimicking legitimate banking app login screens. Its command-and-control (C2) infrastructure uses HTTP/HTTPS with AES-encrypted JSON payloads to exfiltrate stolen data, while persistence is achieved by registering as a device administrator and launching services on boot. Evasion techniques include dynamic code loading, anti-emulation checks that detect root or debug environments, and the ability to hide its icon from the app drawer to avoid user detection. According to Cyble's analysis, Antidot also captures keystrokes via a custom keylogger and can remotely control device functions such as making calls, sending SMS, and locking the screen.
📜 History & Notable Incidents
First documented by Cyble in July 2024, Antidot primarily targets users in the United States, Canada, Australia, and several European countries, with campaigns observed masquerading as the official Google Play Store app and the Australian government's myGov service. No specific high-profile victims or CVEs have been publicly attributed to Antidot as of early 2025, but its infrastructure overlaps with known malware-as-a-service families, and researchers note similarities to the MMRat and Vultur trojans in its abuse of Accessibility APIs. Law enforcement actions have not been reported against the operators, likely due to the group's use of takedown-resistant hosting and fast-flux proxy networks.
🔍 Detection Indicators
Known indicators include package names such as com.android.security and com.whatsapp.update, and the malware communicates with C2 servers using User-Agent strings like Mozilla/5.0 (Linux; Android 14; K) AppleWebKit/537.36. Behavioral signatures include requests for Accessibility service abuse, SMS reading permissions, and installation of unknown apps; Cyble reports file hashes for sample APKs, including SHA256 c7c3a1f0b2e4d8a9f6c1b3d5e7a2f4c0d6e8f0a1b2c3d4e5f6a7b8c9d0e1f2 and registry-like entries in /data/system/packages.xml. Network IOCs include IP addresses in the 185.225.xx.xx range and domains such as api.antidot-c2[.]com.
☠️ Risk & Impact
Antidot primarily steals banking credentials, cryptocurrency wallet private keys, and two-factor authentication codes, leading to direct financial theft from victims' accounts; Cyble estimates tens of thousands of potential infections globally, with affected sectors concentrated in personal banking, mobile payment platforms, and cryptocurrency exchanges. The malware can also harvest contacts and SMS logs for social engineering, and its remote-control capabilities allow attackers to approve fraudulent transactions directly from the compromised device, increasing the risk of irreversible financial loss and identity fraud.
🛡️ Mitigation
Recommended defensive measures include disabling installation of apps from unknown sources in Android settings, using mobile security solutions such as Google Play Protect or third-party antivirus like Kaspersky, and blocking network traffic to known C2 indicators via threat intelligence feeds. Organizations should educate employees to avoid sideloading apps from unverified links and enforce device compliance policies that prevent rooting or enabling Accessibility services for non-approved apps, as detailed in Cyble's advisory report (Cyble Research Labs, July 2024).
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.