BlankBot

Malware

⚠️ Overview

BlankBot is an Android banking trojan first identified in June 2025 by the ThreatFabric research team, operating as a malware-as-a-service (MaaS) targeting Turkish financial institutions through overlay attacks and keylogging. It is attributed to a Turkish-speaking threat actor, possibly linked to the groups behind other mobile trojans such as Grandoreiro, and falls under the categories of banking trojan and keylogger.

🔧 Technical Capabilities

BlankBot abuses Android’s Accessibility Service to capture credentials from banking, cryptocurrency, and social media applications via overlay injections and keylogging; it also performs screen recording and SMS interception. The malware employs a domain generation algorithm (DGA) for command-and-control (C2) communication and uses HTTPS with certificates pinned to evade network monitoring. Persistence is achieved by registering as a device administrator and abusing the foreground service to prevent user removal. Evasion techniques include checking for emulator environments, disabling Google Play Protect, and hiding its icon from the drawer.

📜 History & Notable Incidents

First reported in June 2025 by ThreatFabric, BlankBot was observed in localized campaigns predominantly targeting users in Turkey through phishing SMS messages that impersonate delivery services. No high-profile victims or CVEs have been publicly documented to date; however, the malware shares code similarities with the older Cerberus family and has been actively developed with new features such as streaming keylogging in July 2025.

🔍 Detection Indicators

Indicators include the package name pattern com.android.* (e.g., com.android.update) and the use of the malicious DGA domain pattern *.duckdns.org for C2. ThreatFabric has published SHA-256 hashes of sample APKs in their blog posts; the malware also creates a mutex named BlankBot_Service and modifies the settings secure android_id registry key to evade detection by security apps.

☠️ Risk & Impact

BlankBot poses a high risk to individual users primarily in Turkey, enabling theft of online banking credentials, cryptocurrency wallet seeds, and two-factor authentication codes through intercepted SMS. Financial losses are still being assessed but early reports indicate credential harvesting for at least five major Turkish banks and three cryptocurrency exchanges. The malware’s MaaS model means any cybercriminal can purchase access, expanding the potential impact.

🛡️ Mitigation

Users should avoid installing apps sideloaded from untrusted sources and disable the “Install from unknown apps” permission for messaging apps. Enterprises can deploy mobile threat defense agents with behavioral detection rules for Accessibility Service abuse, and block C2 domains matching DuckDNS patterns. Google has revoked the developer certificates used in these campaigns as of July 2025.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.