FluBot
Malware⚠️ Overview
FluBot is an Android banking trojan and information stealer first identified in December 2020 by the Threat Fabric research team. It is attributed to a financially motivated cybercriminal group known as "GoldFactory" and primarily targets users in Europe, Australia, and the United States. FluBot operates as a malware-as-a-service (MaaS) botnet, enabling credential theft, SMS interception, and lateral propagation via SMS phishing messages.
🔧 Technical Capabilities
FluBot initially spreads via SMS smishing attacks containing links to malicious Android Package Kit (APK) files disguised as package tracking or voicemail apps. Once installed, it requests accessibility service permissions, granting it broad control over the device including keylogging, screen overlay attacks, and interception of SMS messages (including two-factor authentication codes). The malware communicates with a command-and-control (C2) infrastructure over HTTP or WebSocket, using domain generation algorithms (DGAs) to evade takedowns. Persistence is achieved through device administrator privileges and by hiding its icon from the app launcher. Evasion techniques include checking for emulator environments, analyzing GPS coordinates, and using encrypted C2 payloads with SSL pinning.
📜 History & Notable Incidents
FluBot first surfaced in December 2020 targeting Spanish banks and rapidly expanded to over 200 financial institutions worldwide. In February 2022, Europol coordinated Operation "Tao" with law enforcement in the UK, Netherlands, and Australia, arresting key suspects and seizing C2 servers, which temporarily disrupted the botnet. However, a variant known as "Flubot 2.0" resurfaced in 2023 with updated infrastructure. No specific CVEs are associated with FluBot as it relies on social engineering rather than software vulnerabilities.
🔍 Detection Indicators
Known network indicators include C2 domains using patterns like *.ddns.net and *.duckdns.org, with User-Agent strings such as "Dalvik/2.1.0 (Linux; U; Android 10; ...)" commonly seen. On infected devices, FluBot registers a broadcast receiver for com.android.telephony.SMS_RECEIVED and creates mutex names like "lockscreen_show" to control overlay timing. Behavioral signatures include repeated requests for AccessibilityService permissions and outbound SMS messages to premium-rate or foreign numbers. File hashes are not publicly fixed due to constant APK repackaging, but sandbox analysis often reveals the package name "com.android.system" or similar system-like identifiers.
☠️ Risk & Impact
FluBot causes direct financial loss by harvesting banking credentials and intercepting one-time passcodes, enabling fraudulent transactions. It also exfiltrates contact lists to propagate further smishing attacks, converting infected devices into spam bots. The primary affected sectors are retail banking, digital payment platforms, and e-commerce, particularly in Spain, Germany, Australia, and the United Kingdom.
🛡️ Mitigation
Android users should disable "Install from unknown sources" by default and never grant AccessibilityService permissions to unfamiliar apps. Enterprises are recommended to deploy Mobile Threat Defense (MTD) solutions with SMS spam filtering, blocklist known DGA domains, and monitor for sudden spikes in outbound SMS traffic. Google Play Protect will flag FluBot variants as malware, though side-loaded APKs bypass this safeguard.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.