ZooPark (also tracked as Ghimob) is an Android banking trojan first documented by Kaspersky in November 2020, attributed to a Portuguese-speaking threat actor known as “Ghimob Group”. It belongs to the Remote Access Trojan (RAT) and mobile banking malware category, primarily targeting financial institutions in Brazil through overlay attacks and credential theft.
ZooPark abuses Android Accessibility Services to intercept user input, capture screen content, and perform overlay attacks mimicking legitimate banking apps from over 130 financial institutions. It uses Firebase Cloud Messaging (FCM) as its primary Command-and-Control (C2) channel, enabling real-time commands without persistent HTTP connections. The malware achieves persistence by registering as a device administrator and preventing its removal through “Device Admin” locking. Evasion techniques include obfuscation of the APK package, dynamic loading of malicious DEX files at runtime, and checking for emulated environments or debugging tools before activating payloads. Propagation occurs through third-party app stores, phishing SMS messages, and malicious advertisements (malvertising) directing users to download fake updates.
First observed in the wild in October 2020, ZooPark’s major campaign in Brazil targeted clients of Banco do Brasil, Caixa Econômica Federal, and other large banking apps. No specific CVEs are directly associated with ZooPark; instead, it exploits the standard Android Accessibility API (no patched vulnerability required). Law enforcement actions include takedowns of several C2 domains by Brazilian authorities in 2021, though the group later re-emerged with updated variants using TOR-based C2 infrastructure.
Package names commonly observed include “com.power.hot” or “com.whats.sync”, though these vary per campaign. Network IOCs include FCM sender IDs and C2 domains such as “firebaseio.com” endpoints (e.g., “zoopark-default-rtdb.firebaseio.com”). Behavioral signatures include the reading of package lists, enabling Accessibility Service without user consent, and sending SMS messages to premium-rate numbers. Registry keys are irrelevant on Android; instead, mutex-like locks are implemented via SharedPreferences keys like “device_admin_active”.
ZooPark causes direct financial losses by draining bank accounts through stolen credentials and intercepting two-factor authentication (2FA) SMS messages. The malware exfiltrates contact lists, call logs, and SMS data, enabling further social engineering attacks. The primary affected sector is retail banking in Brazil, but variants have been reported targeting users in Portugal, Spain, and Mexico.
Defensive measures include installing apps only from official Google Play Store, disabling “Install from unknown sources”, and revoking Accessibility Service permissions for suspicious apps. Android Device Policy and Mobile Threat Defense (MTD) solutions can detect ZooPark via behavioral signatures and block FCM-based C2 traffic. No specific patch is applicable; user awareness remains the primary defense.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.