Skip to main content

Boteraser | Website and Server Security Solutions

ZooPark

Malware

⚠️ Overview

ZooPark (also tracked as Ghimob) is an Android banking trojan first documented by Kaspersky in November 2020, attributed to a Portuguese-speaking threat actor known as “Ghimob Group”. It belongs to the Remote Access Trojan (RAT) and mobile banking malware category, primarily targeting financial institutions in Brazil through overlay attacks and credential theft.

🔧 Technical Capabilities

ZooPark abuses Android Accessibility Services to intercept user input, capture screen content, and perform overlay attacks mimicking legitimate banking apps from over 130 financial institutions. It uses Firebase Cloud Messaging (FCM) as its primary Command-and-Control (C2) channel, enabling real-time commands without persistent HTTP connections. The malware achieves persistence by registering as a device administrator and preventing its removal through “Device Admin” locking. Evasion techniques include obfuscation of the APK package, dynamic loading of malicious DEX files at runtime, and checking for emulated environments or debugging tools before activating payloads. Propagation occurs through third-party app stores, phishing SMS messages, and malicious advertisements (malvertising) directing users to download fake updates.

📜 History & Notable Incidents

First observed in the wild in October 2020, ZooPark’s major campaign in Brazil targeted clients of Banco do Brasil, Caixa Econômica Federal, and other large banking apps. No specific CVEs are directly associated with ZooPark; instead, it exploits the standard Android Accessibility API (no patched vulnerability required). Law enforcement actions include takedowns of several C2 domains by Brazilian authorities in 2021, though the group later re-emerged with updated variants using TOR-based C2 infrastructure.

🔍 Detection Indicators

Package names commonly observed include “com.power.hot” or “com.whats.sync”, though these vary per campaign. Network IOCs include FCM sender IDs and C2 domains such as “firebaseio.com” endpoints (e.g., “zoopark-default-rtdb.firebaseio.com”). Behavioral signatures include the reading of package lists, enabling Accessibility Service without user consent, and sending SMS messages to premium-rate numbers. Registry keys are irrelevant on Android; instead, mutex-like locks are implemented via SharedPreferences keys like “device_admin_active”.

☠️ Risk & Impact

ZooPark causes direct financial losses by draining bank accounts through stolen credentials and intercepting two-factor authentication (2FA) SMS messages. The malware exfiltrates contact lists, call logs, and SMS data, enabling further social engineering attacks. The primary affected sector is retail banking in Brazil, but variants have been reported targeting users in Portugal, Spain, and Mexico.

🛡️ Mitigation

Defensive measures include installing apps only from official Google Play Store, disabling “Install from unknown sources”, and revoking Accessibility Service permissions for suspicious apps. Android Device Policy and Mobile Threat Defense (MTD) solutions can detect ZooPark via behavioral signatures and block FCM-based C2 traffic. No specific patch is applicable; user awareness remains the primary defense.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.