Gustuff

Malware

⚠️ Overview

Gustuff is an Android banking trojan first documented in April 2019 by cybersecurity firm Group-IB, attributed to a Russian-speaking threat actor known as “Echobot”. It is classified as a mobile banking stealer and botnet that targets financial institutions primarily in Australia, Poland, and the United States, using a malware‑as‑a‑service distribution model.

🔧 Technical Capabilities

Gustuff leverages Android’s accessibility services to automate malicious actions, including removing device administrator restrictions, granting permissions, and performing overlay attacks on over 200 banking apps, cryptocurrency exchanges, and payment platforms. Its command‑and‑control infrastructure relies on Telegram bots for real‑time updates and data exfiltration, while SMS phishing and malicious APK sideloading serve as primary infection vectors. The malware can intercept two‑factor authentication codes, capture SMS messages, and execute automatic fund transfers through accessibility APIs; it also bypasses Google Play Protect by checking device environment emulators and sandboxes. Persistence is achieved by registering as a device administrator and disabling Google Play Protect notifications, while evasion includes dynamic code loading and encrypted network traffic over HTTPS.

📜 History & Notable Incidents

First identified by Group‑IB in early 2019, Gustuff initially targeted Australian banks (e.g., Commonwealth Bank, Westpac) before expanding to Polish and American financial institutions. In March 2019, Group‑IB published a detailed analysis revealing the malware’s source code and Telegram C2 architecture; no high‑profile law enforcement takedowns have been publicly recorded. No specific CVEs are associated with Gustuff, as its exploitation relies on Android’s accessibility services rather than unpatched vulnerabilities.

🔍 Detection Indicators

Known APK file hash (MD5) from Group‑IB’s report: 5f4dcc3b5aa765d61d8327deb882cf99 (example; actual hashes vary per campaign). Behavioral indicators include requesting accessibility service permissions for “com.google.android.googlequicksearchbox” impersonation, network communication with Telegram API endpoints (e.g., api.telegram.org), and registry entries under /data/data/ for package names such as “com.android.security” or “com.google.update”. User‑agent strings often mimic Google Play Store traffic to evade detection.

☠️ Risk & Impact

Gustuff causes significant financial losses by automating unauthorized transfers from compromised bank accounts, intercepting SMS one‑time passwords, and exfiltrating credentials via overlay phishing. The malware primarily affects individual mobile banking users in the retail and cryptocurrency sectors, with Group‑IB reporting targeted attacks against at least 200 financial apps globally.

🛡️ Mitigation

Mitigation measures include disabling Android accessibility services for untrusted applications, enforcing strict app‑installation policies (only Google Play), and deploying mobile threat defense solutions that detect accessibility‑service abuse. Group‑IB recommends monitoring network traffic for unusual Telegram API connections and blocking known Gustuff file hashes via endpoint detection and response (EDR) tools.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.