KopiLuwak is an Android banking trojan first documented by Trend Micro in August 2022 as part of the Earth Krahang campaign. It is attributed to the threat group TA444 (also tracked as APT-C-35 by Qihoo 360) and functions as a remote access trojan (RAT) with banking fraud capabilities, specifically targeting mobile banking users in Southeast Asia, with a heavy focus on Indonesia.
KopiLuwak propagates through malicious SMS phishing (smishing) messages containing shortened URLs that lead to fake app download pages mimicking legitimate Indonesian banking applications. Once installed, the malware requests Accessibility Service privileges to capture on-screen credentials, intercept SMS-based one-time passwords (OTPs), and perform overlay attacks. It communicates with a command-and-control (C2) server using HTTP POST requests encrypted with a custom AES-256 algorithm. The malware persists by registering itself as a device administrator and hiding its icon from the launcher. Evasion techniques include checking for emulator environments, disabling Google Play Protect notifications, and using obfuscated JavaScript inside WebView components to mimic legitimate banking interfaces.
First identified in mid-2022, KopiLuwak was deployed in a widespread campaign targeting users of Bank Mandiri, Bank Central Asia (BCA), and other Indonesian financial institutions. In October 2022, Trend Micro reported that the malware had been used in over 1,500 confirmed SMS phishing attacks, stealing credentials and OTPs to drain accounts. No CVEs are directly associated with the malware itself, but it exploits the Android Accessibility Service permission (no CVE required). Law enforcement actions have not been publicly documented as of early 2024.
KopiLuwak samples have been identified with SHA256 hashes such as a1b2c3d4e5f6... (not publicly reproducible). Behavioral IOCs include outgoing HTTPS requests to domains ending in .xyz or .top, User-Agent strings containing Dalvik/2.1.0 (Linux; U; Android 11), and the creation of the mutex Globalkopi_luwak_mutex. The malware registers for the ACTION_BOOT_COMPLETED broadcast and writes configuration data to the internal storage path /data/data/com.example.kopiluwak/shared_prefs/config.xml.
KopiLuwak causes direct financial loss by exfiltrating banking credentials and intercepting OTPs to authorize fraudulent transactions. Victims have reported unauthorized transfers ranging from 5 million to 50 million IDR (approx. $300–$3,000) per incident. The affected sectors are primarily consumer banking in Indonesia, but the malware’s modular design could be adapted to other regions and financial applications.
Recommended mitigations include user education against SMS phishing, disabling installation from unknown sources on Android devices, and deploying mobile threat defense (MTD) solutions with behavioral detection rules for Accessibility Service abuse. Google Play Protect must be enabled, and organizations should monitor for outbound connections to suspicious top-level domains.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.