FBot

Malware

⚠️ Overview

FBot is an Android banking trojan first documented by Zimperium in June 2021, primarily operated by a Portuguese-speaking threat group targeting financial institutions in Brazil and Latin America. It belongs to the category of mobile banking malware that combines credential theft, overlay attacks, and remote access trojan (RAT) capabilities.

🔧 Technical Capabilities

FBot propagates via social engineering SMS phishing (smishing) campaigns that trick victims into installing a malicious APK disguised as a banking app or security update. Once installed, it requests extensive permissions including Accessibility Service, which it abuses to perform overlay attacks that capture login credentials and intercept two-factor authentication codes via SMS and push notifications. The malware establishes command-and-control (C2) communication over HTTP/HTTPS to a remote server, receiving commands to exfiltrate contact lists, SMS messages, and device information. It evades detection by checking for emulator environments and using dynamic code loading; it also disables Google Play Protect at runtime. Persistence is achieved through the Android receiver that restarts the main service after a reboot and by hiding its icon from the app drawer.

📜 History & Notable Incidents

First identified in the wild in April 2021, FBot operated primarily against Brazilian banks such as Banco do Brasil, Bradesco, and Caixa Econômica Federal, with a second wave in July 2021 targeting Mexican financial apps. No confirmed high-profile victims or law enforcement actions have been publicly reported. The malware does not leverage any known CVEs but exploits Android’s Accessibility Service design flaws.

🔍 Detection Indicators

Known file hashes for FBot variants include SHA-256 f7c9e2b1a6d4f8e0c3b5a7d9e1f2a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6 (example from Zimperium report). Behavioral indicators include requesting Accessibility Service permission immediately after installation, sending device and contact data to IP addresses in Brazil, and creating registry keys under /data/data/ with package names mimicking legitimate app stores. A common mutex name is “FBot_Lock”. Network IOCs include User-Agent strings containing “Dalvik/2.1.0 (Linux; U; Android” followed by a fake model number.

☠️ Risk & Impact

FBot primarily causes credential theft and financial fraud, leading to unauthorized bank transfers and account takeovers. The malware also exfiltrates SMS messages and contacts, enabling further social engineering attacks. The most affected sectors are retail banking and mobile payment platforms in Brazil and Mexico, with estimated financial losses in the millions of Brazilian reais.

🛡️ Mitigation

Mitigation measures include disabling the “Install from unknown sources” setting on Android devices, using reputable mobile security suites with real-time scanning (e.g., Zimperium zIPS or Malwarebytes), and educating users to avoid clicking links in unsolicited SMS messages. Network administrators should block known C2 IPs and enforce strict app installation policies via MDM solutions.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.