Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

AI chipmaker Cerebras down 11% after first public earnings report

June 24, 2026

Aave Founder Warns UK Stablecoin Rules Could Push Issuers Abroad

June 24, 2026

KOSPI Shock Sends Fresh Warning Across Bitcoin And Risk Asse

June 24, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Android Malware Targets Banking Users Through Discord Channels
Android Malware Targets Banking Users Through Discord Channels
Security and Privacy

Android Malware Targets Banking Users Through Discord Channels

July 31, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A sophisticated Android banking Trojan, dubbed “DoubleTrouble,” has recently expanded both its delivery methods and technical capabilities, posing a significant threat to users across Europe.

Initially spread through phishing websites impersonating major banks, the malware now distributes its payload via Discord-hosted APKs, making detection and prevention more difficult.

Researchers at Zimperium have analyzed nine samples from the current campaign and 25 from earlier variants.

In an advisory published on Wednesday, they reported that the latest version of the Trojan offers several new functions designed to steal sensitive data, manipulate device behavior and evade traditional mobile defenses.

Advanced Features Enable Real-Time Surveillance

Once installed, DoubleTrouble disguises itself as a legitimate app using a Google Play icon and prompts users to enable Android’s accessibility services. This access allows the malware to operate stealthily in the background.

A session-based installation method conceals its payload in the app’s resources/raw directory, thereby helping it evade early detection.

The latest iteration of the malware includes a range of advanced features, including:

  • Real-time screen recording through MediaProjection and VirtualDisplay APIs

  • Fake lock screen overlays to steal PINs, passwords and unlock patterns

  • Keylogging via accessibility event monitoring

  • Blocking of specific applications, especially banking or security tools

  • Phishing overlays tailored to mimic legitimate app login screens

Captured data is encoded and transmitted to a remote command-and-control (C2) server. Target data includes credentials from banking apps, password managers and crypto wallets.

By mirroring the device screen in real time, attackers can bypass multi-factor authentication and access sensitive content exactly as the user sees it.

Read more on Android malware targeting financial apps: ToxicPanda Malware Targets Banking Apps on Android Devices

Full Command Set Gives Attackers Deep Control

The Trojan responds to dozens of commands sent from its C2 server, allowing remote operators to simulate taps and swipes, trigger fake UI elements, display black or update screens and control system-level settings.

See also  House Appropriation bill targets SEC's controversial SAB 121 amid budget talks

Commands such as send_password, start_graphical and block_app allow attackers to harvest information while actively obstructing the user’s actions.

Zimperium warned that DoubleTrouble’s use of obfuscation, dynamic overlays and real-time visual capture reflects a trend toward more adaptive and persistent mobile threats. Its continuous evolution and novel distribution methods mark it as a serious concern for both individual users and financial institutions.

Image credit: Marcelo Mollaretti / Shutterstock.com

Source link

Android Banking Channels Discord Malware Targets users
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Zcash Mining Exposure Comes to Wall Street as Fortitude Targets Nasdaq Listing

June 23, 2026

Why the banking industry is fighting a crypto bill

June 23, 2026

Loaded Lions’ Mane City Mobile Heads to iOS and Android as Sign-Ups Begin

June 23, 2026

EU targets privacy coins while leaving Bitcoin transfers untouched

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ripple CEO Says Clarity “Opens Up The US Market” for XRP

January 20, 2024

US Banking Crisis Just Starting, Deposits Slump and Bailout Peaks

September 13, 2023

Opulous Announces Strategic Partnership with PolyTrade

March 1, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

AI chipmaker Cerebras down 11% after first public earnings report

June 24, 2026

Aave Founder Warns UK Stablecoin Rules Could Push Issuers Abroad

June 24, 2026

KOSPI Shock Sends Fresh Warning Across Bitcoin And Risk Asse

June 24, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$62,550.00-2.23%
  • ethereumEthereum(ETH)$1,662.07-3.80%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$576.44-2.37%
  • usd-coinUSDC(USDC)$1.000.01%
  • rippleXRP(XRP)$1.10-2.03%
  • solanaSolana(SOL)$69.34-3.29%
  • tronTRON(TRX)$0.329211-1.07%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.16%
  • HyperliquidHyperliquid(HYPE)$61.02-8.50%