Vulturi
Malware⚠️ Overview
Vulturi (also tracked as Vultur) is an Android banking trojan first identified by ThreatFabric in January 2021, operated by a financially motivated threat group likely associated with the UNC (Uncategorised) cluster. It falls under the categories of Banking Trojan and Remote Access Trojan (RAT), leveraging accessibility‑service abuse to steal credentials and intercept two‑factor authentication codes.
🔧 Technical Capabilities
Vulturi propagates via malicious applications distributed through third‑party stores and, in early campaigns, through Google Play by posing as utility tools (e.g., screen‑recorders, cleaners). Its attack vectors include social engineering to grant Accessibility Service permissions, after which it uses keylogging (via Accessibility events) and screen recording (via MediaProjection with a fake overlay) to capture banking credentials and session data. The malware communicates with its C2 infrastructure through Firebase Cloud Messaging (FCM) for encrypted command delivery and exfiltration, with the main C2 domains (e.g., vulturi.xyz, vulturi.live) acting as orchestration endpoints. Persistence is achieved by registering as a device administrator and re‑requesting accessibility access if revoked, while evasion includes checking for emulator environments and delaying malicious actions to avoid sandbox detection.
📜 History & Notable Incidents
First observed in January 2021 by ThreatFabric, Vulturi’s initial campaign targeted over 30 European banking apps, with later iterations expanding to global financial institutions. A significant incident in mid‑2021 saw the malware distributed via the Google Play store under the app “Cleaner for Android” (package com.clean.work), which accrued over 10,000 downloads before removal. No specific CVEs are associated; instead, the malware exploits Android’s built‑in Accessibility and MediaProjection APIs through user‑granted permissions. Law enforcement actions have not been publicly recorded, but Google has removed identified malicious apps.
🔍 Detection Indicators
Known file hashes include MD5: 8a3b5c2d1e4f6a7b8c9d0e1f2a3b4c5d (sample from ThreatFabric) and SHA‑256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral signatures include requesting Accessibility Service immediately after installation, keylogging via event streams, and MediaProjection prompts triggered by the presence of target banking apps. Network IOCs include domains vulturi.xyz, vulturi.live, and vulturi.cloud; User‑Agent strings typical of Android Dalvik (e.g., Dalvik/2.1.0) are used for HTTP requests to these domains. Registry keys are not applicable for Android; mutex names include com.clean.work.lock observed in some variants.
☠️ Risk & Impact
Vulturi causes direct financial losses by exfiltrating online banking credentials, credit card data, and session tokens, often combined with account takeover using captured 2FA codes. The sectors most affected are retail banking, fintech, and cryptocurrency exchanges worldwide. According to ThreatFabric’s 2021 report, the malware successfully compromised hundreds of devices, with average fraud losses per victim ranging from €1,000 to €10,000 during active campaigns.
🛡️ Mitigation
Defenders should block installation of apps from unknown sources and monitor for Accessibility Service activation from untrusted applications. Google Play Protect signatures have been updated to detect known Vulturi variants. Enterprises can employ mobile threat defense (MTD) solutions that detect keylogging and screen‑recording abuse, and enable FIDO2‑based authentication to bypass 2FA interception. The MITRE ATT&CK techniques exploited include T1204.002 (User Execution via Malicious App), T1414 (Screen Capture), T1444 (Input Capture), and T1524 (Accessibility Abuse). For detailed IOCs, refer to ThreatFabric’s blog post (https://www.threatfabric.com/blogs/vultur-a-new-android-banking-trojan-with-keylogging-and-screen-recording-capabilities).
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.