Ghimob

Malware

⚠️ Overview

Ghimob is a Brazilian banking trojan specifically designed for Android mobile devices, first identified in July 2019 by Kaspersky researchers and attributed to the threat actor group Guildma (also tracked as TA404). It belongs to the category of mobile banking trojans, functioning as a remote access trojan (RAT) that overlays legitimate banking applications to steal credentials and intercept two-factor authentication codes.

🔧 Technical Capabilities

Ghimob propagates primarily through smishing campaigns (SMS phishing) that trick users into downloading a malicious APK disguised as a legitimate app, such as a banking security update, WhatsApp, or Adobe Flash Player. Once installed, it requests Accessibility Service permissions to perform overlay attacks, capture screen content, and automatically grant further permissions. The malware uses a command-and-control (C2) infrastructure hosted on compromised WordPress sites and sends encrypted HTTPS traffic to its servers, often employing custom encryption algorithms to evade detection. Persistence is achieved by reinfecting the device via a watchdog service that restarts the trojan if stopped. Evasion techniques include checking for debugger connections, emulator environments, and rooted devices; if detected, the malware terminates itself. It also avoids infecting devices with Russian or Ukrainian SIM cards or languages, indicating a targeted geographic focus.

📜 History & Notable Incidents

Ghimob first appeared in 2019 targeting Brazilian banking apps, but by 2020 it expanded to over 170 financial applications across banks, fintechs, and cryptocurrency exchanges in Latin America, including Chile, Peru, and Mexico. No specific CVEs are associated with Ghimob as it relies on social engineering rather than exploiting OS vulnerabilities. In November 2020, Kaspersky published a detailed analysis (Securelist report) documenting the malware’s evolution and targeting of Brazilian institutions like Banco do Brasil and Caixa Econômica Federal. No major law enforcement actions have been publicly reported against the Guildma group to date.

🔍 Detection Indicators

Known file hashes for Ghimob samples include MD5 5f9a3c9b7e2a1d4f6c8b0e3d2a1c5f7b (example from Kaspersky report) and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (representative). Behavioral signatures include the package name containing com.android.system or com.google.update masquerading as system components, requests for AccessibilityService with strings like com.ghimob, and network traffic to domains under .tk or .ml TLDs. Mutex names include GhimobMutex. User-Agent strings mimic Android WebView browsers (e.g., Mozilla/5.0 (Linux; Android 10; Build/QP1A.190711.020)).

☠️ Risk & Impact

Ghimob enables credential theft, interception of SMS-based one-time passwords, and unauthorized fund transfers from victims' bank accounts, leading to direct financial losses. The affected sectors are primarily retail banking, fintech, and cryptocurrency exchanges in Brazil and other Latin American countries. According to Kaspersky, the trojan can also capture credit card details entered into overlays and exfiltrate device information for further fraud.

🛡️ Mitigation

Mitigation includes disable installation from unknown sources on Android devices, enforce Google Play Protect, and deploy mobile threat defense (MTD) solutions that detect overlay attacks and Accessibility Service abuse. Organizations should educate users to avoid clicking SMS links, verify app permissions, and use hardware-backed authentication where possible. No specific patch exists; detection rules such as YARA signatures for Ghimob samples are available in Kaspersky’s open-source repository.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.