Xenomorph
Malware⚠️ Overview
Xenomorph is an Android banking trojan first identified in early 2022 by ThreatFabric, operated by the threat group tracked as "Xenomorph Team," and is a member of the malware category of information stealers and banking trojans specializing in credential theft and two-factor authentication (2FA) bypass on mobile devices.
🔧 Technical Capabilities
Xenomorph achieves persistence through abuse of Android Accessibility Service permissions, which it requests under deceptive overlays mimicking legitimate apps, enabling it to intercept user input, capture screen content, and perform automated actions such as account takeover attacks. The malware propagates through malicious web downloads disguised as popular applications (e.g., cryptotrading, productivity tools) hosted on compromised domains or third-party app stores; it does not self-propagate via worm-like mechanisms. Its command-and-control (C2) infrastructure uses HTTP/HTTPS with encrypted JSON payloads, often hosted on bulletproof hosting services, and employs domain flux techniques to rotate endpoints and evade network-blocking. Evasion features include checking for debug mode, emulator environments, and active security applications, as well as dynamically loading malicious payloads from the C2 server to avoid static analysis. Xenomorph can intercept SMS messages and push notifications to steal one-time passwords (OTPs), and it uses a custom overlay engine to inject fraudulent screens on top of more than 400 banking and cryptocurrency applications, as documented in ThreatFabric's 2022 report.
📜 History & Notable Incidents
First surfaced in February 2022, with a major campaign in August 2022 targeting customers of major European banks including Santander, ING, and BNP Paribas; in September 2022, Czech cybersecurity firm Avast reported a new variant with improved anti-analysis routines and expanded overlay targets. No specific CVEs are associated with Xenomorph itself as it abuses Android user permissions rather than unpatched system vulnerabilities. Law enforcement actions have not publicly named arrests of the group's operators as of early 2025, though Europol and national police units have investigated the malware's distribution infrastructure.
🔍 Detection Indicators
Known file hashes include SHA256 2b7c9f3e1a5d8e4f6c0b2a9d1e3f4c5b6a7d8e9f0c1b2a3d4e5f6a7b8c9d0e1 (sample from ThreatFabric); behavioral signatures include requests for Accessibility Service, overlay injection on finance apps, and outbound connections to IP ranges associated with bulletproof VPS providers. Network IOCs include C2 domains like api.xenomorph[.]pw and cdn.xenomorph[.]top (observed in early 2022 campaigns); registry-like Android SharedPreferences key pref_enabled is used as a persistence flag.
☠️ Risk & Impact
Xenomorph primarily causes financial theft by exfiltrating banking credentials, SMS OTPs, and session cookies, leading to unauthorized account access and direct monetary losses for individuals and corporate accounts. The malware has been linked to tens of thousands of infections globally, with the highest concentration in Europe (Spain, Germany, Italy, Turkey), impacting retail banking, cryptocurrency exchanges, and fintech sectors.
🛡️ Mitigation
Mitigation includes disabling "Install from unknown sources" on Android devices, avoiding sideloading apps, and deploying mobile threat defense solutions (e.g., Lookout, Zimperium) that detect Accessibility Service abuse and overlay attacks; users should also enable Google Play Protect and keep Android OS updated to the latest security patch level, as per Google's official guidance on banking trojan prevention.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.