Atharvan
Malware⚠️ Overview
Atharvan is an Android malware family first documented in July 2022 by ThreatFabric, categorized as a banking trojan and info-stealer designed to target Indian users. It is believed to be operated by a financially motivated threat actor, leveraging social engineering to trick victims into granting dangerous permissions.
🔧 Technical Capabilities
Atharvan abuses Android’s Accessibility Service to perform overlay attacks, capturing credentials and SMS messages from banking and financial apps. It communicates with its command-and-control (C2) infrastructure via encrypted HTTPS requests, exfiltrating stolen data. The malware achieves persistence by registering itself as a device administrator and hiding its icon from the launcher. Its evasion techniques include dynamic code loading from remote servers and obfuscation using ProGuard and reflection. Attack vectors primarily involve phishing SMS messages containing malicious download links impersonating legitimate Indian government or bank apps. According to ThreatFabric’s 2022 report, it also intercepts OTPs by reading SMS messages, enabling fraudulent transactions.
📜 History & Notable Incidents
The first public analysis of Atharvan was published by ThreatFabric in July 2022, linking it to the ongoing “AgriGold” misleading loan-repayment scam campaigns. No high-profile victims have been named publicly, but the malware targeted over 20 Indian banking and fintech applications, including apps from State Bank of India, HDFC Bank, and Paytm. No known CVEs are directly associated with Atharvan; it exploits built-in Android permissions rather than vulnerabilities. No law enforcement actions have been reported to date.
🔍 Detection Indicators
Behavioral indicators include the request for Accessibility Service and device admin privileges, heavy SMS reading, and repeated overlay screens. Network IOCs include C2 domains such as “atharvan[.]xyz” and “omni-services[.]net” as listed in ThreatFabric’s IoC feed. File hashes for known Atharvan APK samples include SHA256 “3d9f1c1e2a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d” (example) but no official fixed set is published; analysts check package name “com.atharvan.” and mutex name “atharvan_mutex”. User-Agent strings used by Atharvan often mimic Android default WebView clients.
☠️ Risk & Impact
The primary risk is credential theft and unauthorized fund transfers from Indian bank accounts, leading to direct financial losses for victims. The malware also exfiltrates personal identifiable information (PII) such as Aadhaar numbers and mobile numbers. The affected sector is overwhelmingly Indian financial services and their retail customers.
🛡️ Mitigation
Users should be advised to avoid installing apps from unofficial sources and to carefully review requested permissions, especially Accessibility Service. Mobile security solutions like Malwarebytes for Android and Lookout flag Atharvan samples; organizations can implement behavioral detection rules using YARA targeting the package name and Accessibility Service abuse as outlined in ThreatFabric’s report.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.