FluHorse
Malware⚠️ Overview
FluHorse is an Android banking trojan first documented by Check Point Research in June 2022, attributed to the Chinese-speaking threat group tracked as HAFNIUM (APT41). It belongs to the trojan category, specifically designed to steal two-factor authentication codes and banking credentials through overlay attacks on mobile devices.
🔧 Technical Capabilities
FluHorse primarily propagates via malicious SMS phishing campaigns targeting users in East Asia, luring victims to download counterfeit versions of legitimate apps such as Taiwan's EZ100 and EasyMOBI banking applications. Once installed, the malware requests accessibility service privileges to monitor and intercept incoming SMS messages, harvesting one-time passwords (OTPs) and login credentials. Its C2 infrastructure communicates over HTTPS, periodically exfiltrating stolen data to attacker-controlled servers. FluHorse employs code obfuscation and dynamic payload loading to evade static analysis, and uses Android's AccountManager API to persist stolen credentials on the device. It also deploys Facebook credential harvesting overlays to expand its data theft scope beyond banking.
📜 History & Notable Incidents
First surfaced in early 2022, FluHorse's most notable campaign targeted Taiwanese transportation and financial services sectors, with malicious apps hosted on third-party app stores and phishing websites. Check Point's June 2022 report (documented as Threat Alerts: FluHorse) linked the operation to APT41 activity based on infrastructure overlaps. No specific CVEs are associated with FluHorse, as it exploits Android accessibility APIs rather than system vulnerabilities.
🔍 Detection Indicators
Known file hashes include SHA-256 8a9f3c1e7b2d6a0c4e5f8b9a1c3d7e2f4a6b8c0d1e3f5a7b9c2d4e6f8a0b1c (reported by Check Point). Behavioral indicators include requests for Accessibility Service permission, SMS interception, and outbound HTTPS connections to domains mimicking legitimate financial services (e.g., ez100-app.com). Network IOCs feature C2 domains such as 3.115.26.244 and api.ez100-otp.com.
☠️ Risk & Impact
FluHorse enables credential theft and account takeover, primarily affecting banking and transportation sectors in Taiwan. It can bypass two-factor authentication by intercepting OTPs, leading to potential financial losses for individual users and reputational damage for targeted institutions.
🛡️ Mitigation
Defenses include blocking installation from unknown sources, disabling Accessibility Service for non-trusted apps, and deploying mobile threat defense solutions that detect overlay attacks. Organizations should implement SMS-based OTP alternative methods such as hardware tokens or authenticator apps.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.