Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

US Crypto Industry Groups Urge Congress to Pass Original Mining and Staking Tax Bill

June 24, 2026

Altcoin supply Is tightening – Traders, is the altseason narrative back?

June 24, 2026

WePlay Partners with Sinkum Unchis to Support Youth Football Development in Peru’s Quechua-Speaking Communities

June 24, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Android Malware Targets Banking Users Through Discord Channels
Android Malware Targets Banking Users Through Discord Channels
Security and Privacy

Android Malware Targets Banking Users Through Discord Channels

July 31, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A sophisticated Android banking Trojan, dubbed “DoubleTrouble,” has recently expanded both its delivery methods and technical capabilities, posing a significant threat to users across Europe.

Initially spread through phishing websites impersonating major banks, the malware now distributes its payload via Discord-hosted APKs, making detection and prevention more difficult.

Researchers at Zimperium have analyzed nine samples from the current campaign and 25 from earlier variants.

In an advisory published on Wednesday, they reported that the latest version of the Trojan offers several new functions designed to steal sensitive data, manipulate device behavior and evade traditional mobile defenses.

Advanced Features Enable Real-Time Surveillance

Once installed, DoubleTrouble disguises itself as a legitimate app using a Google Play icon and prompts users to enable Android’s accessibility services. This access allows the malware to operate stealthily in the background.

A session-based installation method conceals its payload in the app’s resources/raw directory, thereby helping it evade early detection.

The latest iteration of the malware includes a range of advanced features, including:

  • Real-time screen recording through MediaProjection and VirtualDisplay APIs

  • Fake lock screen overlays to steal PINs, passwords and unlock patterns

  • Keylogging via accessibility event monitoring

  • Blocking of specific applications, especially banking or security tools

  • Phishing overlays tailored to mimic legitimate app login screens

Captured data is encoded and transmitted to a remote command-and-control (C2) server. Target data includes credentials from banking apps, password managers and crypto wallets.

By mirroring the device screen in real time, attackers can bypass multi-factor authentication and access sensitive content exactly as the user sees it.

Read more on Android malware targeting financial apps: ToxicPanda Malware Targets Banking Apps on Android Devices

Full Command Set Gives Attackers Deep Control

The Trojan responds to dozens of commands sent from its C2 server, allowing remote operators to simulate taps and swipes, trigger fake UI elements, display black or update screens and control system-level settings.

See also  Wall Street insiders hopeful about new banking infrastructure built on blockchain

Commands such as send_password, start_graphical and block_app allow attackers to harvest information while actively obstructing the user’s actions.

Zimperium warned that DoubleTrouble’s use of obfuscation, dynamic overlays and real-time visual capture reflects a trend toward more adaptive and persistent mobile threats. Its continuous evolution and novel distribution methods mark it as a serious concern for both individual users and financial institutions.

Image credit: Marcelo Mollaretti / Shutterstock.com

Source link

Android Banking Channels Discord Malware Targets users
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Zcash Mining Exposure Comes to Wall Street as Fortitude Targets Nasdaq Listing

June 23, 2026

Why the banking industry is fighting a crypto bill

June 23, 2026

Loaded Lions’ Mane City Mobile Heads to iOS and Android as Sign-Ups Begin

June 23, 2026

EU targets privacy coins while leaving Bitcoin transfers untouched

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Games need decentralized randomness to be fair

October 22, 2023

0.1% levy could raise €3B–€4B a year

June 2, 2026

Immutable and AWS Unite to Accelerate Web3 Onboarding

October 11, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

US Crypto Industry Groups Urge Congress to Pass Original Mining and Staking Tax Bill

June 24, 2026

Altcoin supply Is tightening – Traders, is the altseason narrative back?

June 24, 2026

WePlay Partners with Sinkum Unchis to Support Youth Football Development in Peru’s Quechua-Speaking Communities

June 24, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$62,714.00-1.32%
  • ethereumEthereum(ETH)$1,667.82-2.77%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$577.54-1.50%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • rippleXRP(XRP)$1.10-1.27%
  • solanaSolana(SOL)$69.65-2.45%
  • tronTRON(TRX)$0.329062-0.94%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.16%
  • HyperliquidHyperliquid(HYPE)$61.62-7.17%