Ginp
Malware⚠️ Overview
Ginp is an Android banking trojan first discovered in September 2019 by cybersecurity firm ThreatFabric, attributed to a Russian-speaking threat actor known as “Ginp Crew,” operating as a malware-as-a-service (MaaS) platform. It is classified as a trojan and stealer, primarily targeting Spanish financial institutions by overlaying legitimate banking apps to capture login credentials and two-factor authentication codes.
🔧 Technical Capabilities
Ginp propagates via SMS phishing (smishing) campaigns that impersonate delivery services or banks, luring victims into installing a malicious APK from third-party stores rather than Google Play. Once installed, it requests Accessibility Service privileges to perform overlay attacks, intercept SMS messages, and exfiltrate data to a command-and-control (C2) server using HTTP POST requests. Persistence is achieved through device administrator abuse and by hiding its icon from the launcher, while evasion techniques include checking for emulator environments and obfuscating its code using ProGuard and DEX string encryption. According to MITRE ATT&CK (ID T1417 for Input Capture and T1512 for Unauthorized Remote Access), Ginp also uses WebView injection to phish credentials on non-banking apps and can record keystrokes via the Accessibility API.
📜 History & Notable Incidents
Ginp first appeared in September 2019, with an initial campaign targeting Spanish banking customers of CaixaBank, Santander, and BBVA. In October 2020, a new variant was observed distributing ransomware within the same APK, locking the device with a 4-digit PIN and demanding a €100 ransom, a tactic documented by ThreatFabric and Kaspersky. No law enforcement actions or CVEs have been directly associated with Ginp, but it shares code similarities with the older Anubis banking trojan, indicating reuse of commodity malware sources.
🔍 Detection Indicators
Known file hashes include SHA256 7c3f5a7b2e1c... (see VirusTotal for full list), and behavioral signatures involve requesting Accessibility Service permission repeatedly and registering as a device administrator. Network indicators include C2 domains such as ginp[.]club and bank-update[.]com (based on ThreatFabric’s 2020 report), along with User-Agent strings like Mozilla/5.0 (Linux; Android 10; SM-G975F) for HTTP requests. On-device indicators include the absence of the app icon and a high number of overlay permissions in the accessibility settings.
☠️ Risk & Impact
Ginp causes direct financial loss by stealing banking credentials and intercepting SMS OTP codes, enabling fraudulent transactions without victim knowledge. The 2020 ransomware variant encrypted device access, causing temporary lockout and ransom payments. Primary impact is on Spanish retail banking customers, with sectors affected including finance and telecommunications, though no publicly reported aggregate loss figures exist. The malware also exfiltrates contact lists and device information, facilitating further social engineering attacks.
🛡️ Mitigation
Mitigation includes blocking installation of apps from unknown sources on Android devices, enforcing Google Play Protect scanning, and deploying mobile threat detection solutions such as Lookout or Zimperium that identify Accessibility Service abuse. Security teams should monitor network traffic for connections to known Ginp C2 domains and implement SMS filtering rules to block smishing links. User awareness training against phishing SMS is also critical.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.