Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Copilot Vulnerability Lets Attackers Hijack Accounts
August 4, 2026
Microsoft Hardens NuGet Security with Shorter API Key Lifespans
August 4, 2026
How SOCs Detect and Stop AI Phishing Attacks Bypassing Email Gateways
August 4, 2026
Home/Threats/Android Banking Trojan OverlayPhantom Exploits Accessibility Service
Threats

Android Banking Trojan OverlayPhantom Exploits Accessibility Service

Key Takeaways OverlayPhantom, a new Android banking trojan, is actively targeting users in ten countries, including the US, UK, and Australia. The malware employs a two-stage infection process, using...

Sarah simpson
Sarah simpson
June 1, 2026 4 Min Read
66 0

Key Takeaways

  • OverlayPhantom, a new Android banking trojan, is actively targeting users in ten countries, including the US, UK, and Australia.
  • The malware employs a two-stage infection process, using deceptive dropper apps disguised as legitimate system updates or popular applications like ID Austria and TikTok.
  • It leverages Android’s Accessibility Service to gain persistent control over infected devices, enabling attackers to execute over 30 remote commands, including live screen streaming and simulating user interactions.
  • OverlayPhantom deploys sophisticated overlay attacks, presenting fake login pages over genuine banking and cryptocurrency applications to steal credentials.

Sophisticated Android Banking Trojan “OverlayPhantom” Targets Financial Accounts Globally

A newly identified Android banking trojan, dubbed OverlayPhantom, is actively compromising users across ten nations, posing a significant threat to banking credentials, financial data, and cryptocurrency holdings. This advanced malware has been operational since May 2025, propagating through malicious links that mimic downloads from legitimate and widely recognized applications.

Table Of Content

  • Key Takeaways
  • Sophisticated Android Banking Trojan “OverlayPhantom” Targets Financial Accounts Globally
  • How OverlayPhantom Operates
  • Overlay Attacks Targeting Banking and Cryptocurrency Apps
  • What You Should Do

OverlayPhantom’s infection mechanism is particularly concerning due to its two-stage approach. The initial stage involves a dropper application masquerading as either ID Austria, the official Austrian government identity application, or the globally popular social media platform, TikTok. Victims are then tricked into installing what appears to be a routine system update, at which point the sophisticated malware establishes its foothold.

Researchers at Cyble Research and Intelligence Labs (CRIL) discovered OverlayPhantom during their investigation into government-themed URL impersonation campaigns. In a report shared with Cyber Security News (CSN), Cyble detailed that the malware targets over 180 banking, financial services, and cryptocurrency applications across the United States, Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain, and the United Kingdom.

Once installed, OverlayPhantom further conceals its presence by posing as “Google Play Services,” making it exceptionally difficult for average users to detect or remove. From this hidden position, it exploits Android’s Accessibility Service—a feature designed to assist users with disabilities—to gain persistent, high-level control over the compromised device. This access allows threat actors to issue more than 30 remote commands, enabling them to manipulate the device unnoticed by the victim.

The extensive geographical reach and the technical sophistication of OverlayPhantom suggest a well-resourced, financially motivated group orchestrating a large-scale fraud operation. With a target list encompassing over 180 applications and victims spread across major Western markets, OverlayPhantom represents a substantial and ongoing threat.

How OverlayPhantom Operates

The abuse of Android’s Accessibility Service is central to OverlayPhantom’s operational power. After a victim is lured into granting this critical permission—often guided by a deceptive tutorial embedded within the dropper app—the malware establishes a connection to its Command and Control (C&C) server, located at IP address 199.217[.]99[.]122.

The C&C communication is segmented across three distinct ports, enhancing reliability and evasion. Port 9091 is utilized for dispatching commands to the infected device, port 9092 handles device status updates, and port 9090 is dedicated to live screen streaming. This multi-port architecture ensures robust and persistent communication. The malware employs Android’s MediaProjection API to stream the victim’s screen in near real-time, using JPEG compression, providing attackers with an immediate visual feed of all on-device activity.

The remote command capabilities of OverlayPhantom are extensive. Attackers can simulate various user inputs, including taps, swipes, and long presses. They can also lock the screen, manipulate clipboard contents, display fraudulent notifications, and launch overlay windows designed to capture sensitive information such as PIN codes or passwords. These comprehensive controls enable threat actors to execute unauthorized financial transactions without the victim’s awareness.

Google Play Update lure to install OverlayPhantom (Source - Cyble)
Google Play Update lure to install OverlayPhantom (Source – Cyble)

Overlay Attacks Targeting Banking and Cryptocurrency Apps

OverlayPhantom carries a hardcoded list of target applications within its codebase. When a user opens a banking or financial application, the malware covertly checks if the app is on its predefined list. Upon identifying a match, it dynamically retrieves and renders a deceptive HTML phishing page within a WebView layer, superimposing it directly over the legitimate application interface. This counterfeit screen is meticulously designed to appear identical to the authentic application.

Unsuspecting victims then enter their credentials, believing they are logging into their genuine bank or cryptocurrency wallet. This sensitive data is immediately harvested and transmitted to the C&C server, leaving no discernible trace of compromise. This highly effective overlay technique is a primary reason why OverlayPhantom is so potent and challenging for victims to detect.

Counterfeit HTML phishing pages in the APK file (Source - Cyble)
Counterfeit HTML phishing pages in the APK file (Source – Cyble)

What You Should Do

  • Download Apps Only from Official Stores: Restrict app downloads exclusively to trusted platforms like the Google Play Store. Avoid installing applications from third-party sources or direct links.
  • Exercise Caution with Links: Be highly suspicious of links received via SMS, email, or social media, especially those prompting application downloads or system updates.
  • Review Accessibility Permissions: Never grant Accessibility Service permissions to any unfamiliar or suspicious application. Understand the implications of such permissions before enabling them.
  • Enable Multi-Factor Authentication (MFA): Implement MFA on all banking, financial, and cryptocurrency applications to add a critical layer of security, protecting accounts even if credentials are stolen.
  • Keep Software Updated: Regularly update your Android operating system and all installed applications. Security patches frequently address vulnerabilities that malware like OverlayPhantom exploits.

Indicators of Compromise (IoCs):-

Type Indicator Description
URL hxxps://bitlrewards-app[.]com/api/download/IDAustria Distribution URL used to spread OverlayPhantom
IP 199.217[.]99[.]122 C&C server IP address
File Hash (SHA-256) 9ef37376bfaa18e193cc72218924ad8ebf56d2667d348f0eae5ae6ec45ab8775f OverlayPhantom malware sample hash
File Hash (SHA-256) 8b614a2918378063d6e6655b676ceb52ae65b1510e2cc08087fcac31acb7aeb8d OverlayPhantom malware sample hash
File Hash (SHA-256) dc1f2a75f3d5b5bd054a5367bd5015ebc90f3453d63c7cce438c12dc2ae86a OverlayPhantom malware sample hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarePatchphishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Red Hat Cloud Services NPM Flaw Lets Attackers Steal Credentials

Next Post

Critical Docker, Kubernetes Flaws Let Attackers Compromise Host Systems

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
CISA Warns of Critical N-able N-central Auth Bypass (CVE-2023-47248) Exploited In Attacks
August 4, 2026
Critical CUPS Vulnerability (CVE-2023-4586) Lets Attackers Gain Root Privileges
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us