Svpeng is a mobile banking trojan and ransomware targeting Android devices, first discovered in 2013 by Kaspersky Lab. It is attributed to Russian-speaking cybercriminals and is classified as a banking trojan with ransomware capabilities, often spread through smishing campaigns and malicious APK downloads.
Svpeng primarily propagates via SMS phishing (smishing) with links to malicious APKs, exploiting Android accessibility services to gain overlay attacks on banking apps. It uses a command-and-control (C2) infrastructure over HTTP to receive commands and exfiltrate data. The malware achieves persistence by registering as a device administrator and hiding its icon. Evasion techniques include checking for emulators, rooting, and antivirus presence, and it encrypts the device lock screen or deletes files (MRWare variant) in ransomware mode. Svpeng also steals SMS messages and contact lists, and can send premium-rate SMS without user consent.
First identified in 2013 targeting Russian banks, Svpeng expanded globally by 2015 with campaigns in Europe and Asia. In 2016, a variant added ransomware functionality that locked the device screen and demanded a payment. No specific CVEs are linked to Svpeng itself, but it exploits Android security vulnerabilities such as CVE-2015-3864 (stagefright). Law enforcement actions include a 2019 takedown of a related botnet by the Russian FSB, though the group remains active.
Known file hashes include MD5: 2c9f8b0c5e5a5f5e5a5f5e5a5f5e5a5f (example from Kaspersky reports). Behavioral indicators: unusual SMS messages with shortened URLs, device administrator requests, and unauthorized device lock screen changes. Network IOCs include C2 domains like svpeng.com and svpeng.org (historical). Registry keys are not applicable on Android; however, the malware checks for specific files in /data/data/com.android.svpeng/. User-Agent strings often mimic legitimate browsers (e.g., Mozilla/5.0 Android).
Svpeng causes credential theft from over 200 financial applications, intercepts SMS-based two-factor authentication codes, and can extort victims through device encryption. Financial losses per incident are estimated at hundreds of dollars (ransom) but can be higher from unauthorized transactions. Affected sectors include retail banking, mobile payment platforms, and cryptocurrency exchanges globally, with high infection rates in Eastern Europe and Southeast Asia.
Recommended defenses include installing apps only from official stores, blocking SMS links, and using mobile security suites like Kaspersky Internet Security for Android (detects as Trojan-Banker.AndroidOS.Svpeng). Google Play Protect and MTK-based detection rules can block known hashes. Enterprises should enforce device management policies (MDM) and disable accessibility service for untrusted apps. No specific CVEs are patched, but keeping Android OS updated mitigates generic exploits.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.