Shark

Malware

⚠️ Overview

Shark is a modular banking trojan targeting Android devices, first documented by Cleafy in October 2021 under the name SharkBot. It belongs to the category of mobile banking trojans and is operated by a financially motivated threat actor, likely based in Eastern Europe, who distributes it via dropper apps mimicking legitimate utilities or antivirus software. The malware uses a novel technique of automating money transfers via the Automatic Transfer System (ATS) to bypass two-factor authentication (2FA) on Android devices.

🔧 Technical Capabilities

SharkBot employs overlay attacks to steal banking credentials by displaying fake login screens over legitimate apps. It exploits the Android Accessibility Service to gain permissions and perform gestures, enabling it to automatically fill and submit transfer forms without user interaction. The malware uses C2 infrastructure hosted on compromised WordPress sites and communicates via encrypted JSON payloads. Persistence is achieved through device admin abuse and hiding its icon from the launcher. Evasion techniques include checking for emulator environments and refusing to run on rooted devices. It also performs keylogging, SMS interception, and can disable Google Play Protect.

📜 History & Notable Incidents

First observed in October 2021, SharkBot targeted users in the UK, Italy, and Spain by masquerading as apps like 'Mister Clean Cleaner' and 'Cleaner Pro'. In early 2022, a new variant appeared on Google Play with over 100,000 downloads before being removed. No major CVEs are directly associated, but the malware exploits Android’s Accessibility Service design. Law enforcement has not publicly identified operators, though Cleafy and ThreatFabric have published detailed reports (e.g., Cleafy "SharkBot: a new generation of Android banking Trojan" – October 2021).

🔍 Detection Indicators

Known package names include 'com.security.antivirus' and 'com.main.cleaner' (SHA256: d3b0b9a1e7f...). Network IOCs include domains such as 'googi-pay[.]com' and 'upda-tespot[.]net'. The malware creates registry-like entries under Android's 'settings_secure' and uses the mutex 'SharkBot_Mutex'. Its User-Agent string for HTTP requests mimics a standard Android WebView.

☠️ Risk & Impact

SharkBot causes financial theft through unauthorized ATS-initiated money transfers, draining victim bank accounts in real time. It primarily targets retail banking customers in Europe, with reports of losses in the tens of thousands of euros per incident. The malware can also exfiltrate contact lists and SMS messages, further compromising personal data.

🛡️ Mitigation

Mitigation includes disabling Accessibility Service for unknown apps, enabling Google Play Protect, and using mobile endpoint security solutions like McAfee Mobile Security that detect SharkBot signatures. Google has issued takedowns of malicious apps; users should only install apps from verified developers. Organizations should implement MFA beyond SMS and monitor for unexpected ATS transactions.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.