Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Pi Network’s CiDi Games unveils blockchain gaming roadmap days before Consensus 2026

May 5, 2026

270K BTC bought in 30 days – Is Bitcoin ready to break out?

May 5, 2026

New Bill Could Pause Crypto Mining in Michigan

May 5, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Android Malware Targets Banking Users Through Discord Channels
Android Malware Targets Banking Users Through Discord Channels
Security and Privacy

Android Malware Targets Banking Users Through Discord Channels

July 31, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A sophisticated Android banking Trojan, dubbed “DoubleTrouble,” has recently expanded both its delivery methods and technical capabilities, posing a significant threat to users across Europe.

Initially spread through phishing websites impersonating major banks, the malware now distributes its payload via Discord-hosted APKs, making detection and prevention more difficult.

Researchers at Zimperium have analyzed nine samples from the current campaign and 25 from earlier variants.

In an advisory published on Wednesday, they reported that the latest version of the Trojan offers several new functions designed to steal sensitive data, manipulate device behavior and evade traditional mobile defenses.

Advanced Features Enable Real-Time Surveillance

Once installed, DoubleTrouble disguises itself as a legitimate app using a Google Play icon and prompts users to enable Android’s accessibility services. This access allows the malware to operate stealthily in the background.

A session-based installation method conceals its payload in the app’s resources/raw directory, thereby helping it evade early detection.

The latest iteration of the malware includes a range of advanced features, including:

  • Real-time screen recording through MediaProjection and VirtualDisplay APIs

  • Fake lock screen overlays to steal PINs, passwords and unlock patterns

  • Keylogging via accessibility event monitoring

  • Blocking of specific applications, especially banking or security tools

  • Phishing overlays tailored to mimic legitimate app login screens

Captured data is encoded and transmitted to a remote command-and-control (C2) server. Target data includes credentials from banking apps, password managers and crypto wallets.

By mirroring the device screen in real time, attackers can bypass multi-factor authentication and access sensitive content exactly as the user sees it.

Read more on Android malware targeting financial apps: ToxicPanda Malware Targets Banking Apps on Android Devices

Full Command Set Gives Attackers Deep Control

The Trojan responds to dozens of commands sent from its C2 server, allowing remote operators to simulate taps and swipes, trigger fake UI elements, display black or update screens and control system-level settings.

See also  Bitcoin: Are users losing interest in Ordinals? This data suggests…

Commands such as send_password, start_graphical and block_app allow attackers to harvest information while actively obstructing the user’s actions.

Zimperium warned that DoubleTrouble’s use of obfuscation, dynamic overlays and real-time visual capture reflects a trend toward more adaptive and persistent mobile threats. Its continuous evolution and novel distribution methods mark it as a serious concern for both individual users and financial institutions.

Image credit: Marcelo Mollaretti / Shutterstock.com

Source link

Android Banking Channels Discord Malware Targets users
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Ripple Shares DPRK Threat Data on Fraud Domains, Wallets, Campaigns

May 5, 2026

WarmySender Reaches 15,000 Users, Reinforcing Position as Top Instantly Alternative

May 4, 2026

Crypto News Today: AlphaPepe Presale Nears $1.1M Raised Whilst Cardano Price Prediction Targets $5.00

May 3, 2026

Crypto industry backs CLARITY Act yield compromise, pushes Senate Banking for markup

May 2, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Here’s the Latest Update on Ripple Vs SEC As Both Parties File New Motions

January 14, 2024

Tom Emmer Sponsoring Amendment To Prevent Gary Gensler From ‘Weaponizing the SEC’ Against Digital Assets

September 11, 2023

Marathon Digital warms 80,000 Finnish homes with heat generated from Bitcoin mining

December 21, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Pi Network’s CiDi Games unveils blockchain gaming roadmap days before Consensus 2026

May 5, 2026

270K BTC bought in 30 days – Is Bitcoin ready to break out?

May 5, 2026

New Bill Could Pause Crypto Mining in Michigan

May 5, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$80,567.000.92%
  • ethereumEthereum(ETH)$2,368.850.04%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.40-1.08%
  • binancecoinBNB(BNB)$626.53-0.61%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$84.48-0.77%
  • tronTRON(TRX)$0.3401990.17%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.77%
  • dogecoinDogecoin(DOGE)$0.110960-0.85%