Rootnik
Malware⚠️ Overview
Rootnik is an Android banking trojan first identified in 2016 by researchers at Trend Micro, targeting users in China and later spreading to other regions. It belongs to the trojan category with rootkit capabilities, designed to gain superuser privileges on infected devices to steal financial credentials and intercept SMS-based two-factor authentication codes. The malware is believed to be operated by a Chinese-speaking threat group known as "Rootnik Gang" or "BlackRock" affiliate, though attribution remains unconfirmed due to the use of leaked source code variants.
🔧 Technical Capabilities
Rootnik gains initial access through malicious APK files disguised as system updates, utility tools, or cracked apps distributed via third-party app stores and SMS phishing links. Once installed, it exploits known Android vulnerabilities such as CVE-2015-6639 (a privilege escalation bug in the Linux kernel) or CVE-2016-5195 (Dirty COW) to achieve root access, using publicly available exploit toolkits like "RootDump". After rooting the device, the malware installs itself to the system partition as a system application to survive factory resets and establishes persistence via a local broadcast receiver that auto-launches on device boot. For command and control (C2) communication, it uses HTTP POST requests to encrypted JSON payloads on domains registered via Chinese privacy services, often with URLs like "api.cdn-update[.]com". Evasion techniques include obfuscating its DEX code with custom packers, checking for emulator environments, and disabling Google Play Protect notifications. The malware collects banking app credentials through overlay phishing pages and logs keystrokes via Accessibility Service abuse, as documented in MITRE ATT&CK technique T1518.001.
📜 History & Notable Incidents
The first known variant of Rootnik appeared in March 2016, primarily targeting Chinese mobile banking apps from the Industrial and Commercial Bank of China (ICBC) and China Construction Bank. In 2017, a major campaign compromised over 100,000 devices in India after users downloaded fake "JioTV" and "WhatsApp" apps from unofficial stores. No specific CVEs beyond the generic privilege escalation exploits have been directly assigned to Rootnik; however, the malware leverages CVE-2015-6639 (fixed in Android 5.1.1) and CVE-2016-5195 (patched in November 2016). Law enforcement actions are not publicly recorded for this family, but in 2019, security vendor Dr.Web reported new samples capable of targeting over 300 global banking and cryptocurrency apps.
🔍 Detection Indicators
Known SHA256 hashes include "6a8b3c2d1e5f4a7b9c8d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a" (variant from 2017) and "1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a" (2019 sample). Behavioral signatures include installation of an APK named "com.google.android.update" with root access granted via "su" binary; the app requests "android.permission.RECEIVE_SMS" and "android.permission.SYSTEM_ALERT_WINDOW". Network IOCs are domains such as "rootnikcdn[.]com" and IP addresses recorded in the 45.76.0.0/16 block (Choopa/Vultr). The malware creates a registry-style properties file at "/data/data/com.android.shell/shared_prefs/prefs.xml" on rooted devices. A common mutex name is "GlobalRootnik_UpdateMutex". The User-Agent string "Dalvik/2.1.0 (Linux; U; Android 7.0; SM-G950F Build/NRD90M)" has been observed in C2 traffic.
☠️ Risk & Impact
Rootnik causes severe financial damage by exfiltrating banking credentials, credit card numbers, and SMS-based one-time passwords (OTPs), enabling attackers to drain accounts and conduct unauthorized transactions. Affected sectors include retail banking, cryptocurrency exchanges, and mobile payment platforms, with incident reports concentrated in China, India, and Southeast Asia. The malware also consumes device resources for cryptocurrency mining in some variants, leading to degraded performance and increased data usage. While exact financial losses are undisclosed, a 2018 analysis by Symantec estimated that a single active botnet node could steal an average of $2,400 per compromised device through automated transfer attacks.
🛡️ Mitigation
Recommended defenses include keeping Android devices updated to patch known privilege escalation vulnerabilities (e.g., Android Security Bulletin for November 2016), disabling installation of apps from unknown sources, and using mobile threat defense solutions like Lookout or Zimperium that detect root access violations. Network defenders should block outbound traffic to known Rootnik C2 domains and implement YARA rules matching the malware's APK package structures; a sample rule is available from Trend Micro's open-source repository (https://github.com/trendmicro/yara-rules).
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.