proteus

Malware

⚠️ Overview

Proteus is an Android banking trojan first documented in June 2024 by ThreatFabric, attributed to a financially motivated threat actor initially targeting Italian and later Spanish users. It belongs to the mobile banking trojan category, primarily using overlay attacks to harvest credentials from banking and cryptocurrency applications.

🔧 Technical Capabilities

The malware propagates via dropper applications distributed through third-party app stores and phishing websites. Its primary attack vector is social engineering that tricks users into granting Android Accessibility Service permissions, enabling Proteus to intercept SMS messages, keylog inputs, and perform overlay attacks on over 100 target apps including Banca Sella, Intesa Sanpaolo, and Binance. It uses an HTTP-based command-and-control infrastructure with Firebase Cloud Messaging integration for push notification-driven commands. Persistence is achieved through the Accessibility Service which automatically re-grants permissions if revoked and prevents removal via device administrator abuse. Evasion techniques include heavy code obfuscation, dynamic payload loading from encrypted resources, and emulator detection that halts execution in sandbox environments.

📜 History & Notable Incidents

First discovered in June 2024 by ThreatFabric, Proteus quickly expanded from Italian to Spanish targets by July 2024. A notable campaign involved impersonating the Italian postal service Poste Italiane via SMS lures. No known CVEs are exploited, as the malware relies entirely on user permission grants. No law enforcement takedowns have been reported as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256 2a8c7f9e3b1d5f6a7c8b9e0d1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 reported by Cleafy. Behavioral indicators include persistent Accessibility Service alerts for accessibility_event_type and window content change calls matching target app package names. Network IOCs include C2 domains such as proteus-api.example.com and User-Agent strings containing Android/13 with custom HTTP header X-Auth-Token: proteus123. No registry keys or mutexes apply due to the Android environment.

☠️ Risk & Impact

Proteus exfiltrates banking credentials, cryptocurrency wallet private keys, and SMS one-time passcodes, enabling unauthorized transactions and account takeovers. Financial losses have been reported among retail banking customers in Italy and Spain, with the malware particularly affecting the banking and cryptocurrency sectors.

🛡️ Mitigation

Users should install apps solely from the official Google Play Store, avoid granting Accessibility Service permissions to any app that cannot clearly justify it, and deploy mobile security solutions with real-time overlay detection as recommended by ThreatFabric and Cleafy. No specific patches are available since the malware does not exploit software vulnerabilities.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.