Android Banking Trojan OverlayPhantom Exploits Accessibility Service
Key Takeaways OverlayPhantom, a new Android banking trojan, is actively targeting users in ten countries, including the US, UK, and Australia. The malware employs a two-stage infection process, using...
Key Takeaways
- OverlayPhantom, a new Android banking trojan, is actively targeting users in ten countries, including the US, UK, and Australia.
- The malware employs a two-stage infection process, using deceptive dropper apps disguised as legitimate system updates or popular applications like ID Austria and TikTok.
- It leverages Android’s Accessibility Service to gain persistent control over infected devices, enabling attackers to execute over 30 remote commands, including live screen streaming and simulating user interactions.
- OverlayPhantom deploys sophisticated overlay attacks, presenting fake login pages over genuine banking and cryptocurrency applications to steal credentials.
Sophisticated Android Banking Trojan “OverlayPhantom” Targets Financial Accounts Globally
A newly identified Android banking trojan, dubbed OverlayPhantom, is actively compromising users across ten nations, posing a significant threat to banking credentials, financial data, and cryptocurrency holdings. This advanced malware has been operational since May 2025, propagating through malicious links that mimic downloads from legitimate and widely recognized applications.
Table Of Content
OverlayPhantom’s infection mechanism is particularly concerning due to its two-stage approach. The initial stage involves a dropper application masquerading as either ID Austria, the official Austrian government identity application, or the globally popular social media platform, TikTok. Victims are then tricked into installing what appears to be a routine system update, at which point the sophisticated malware establishes its foothold.
Researchers at Cyble Research and Intelligence Labs (CRIL) discovered OverlayPhantom during their investigation into government-themed URL impersonation campaigns. In a report shared with Cyber Security News (CSN), Cyble detailed that the malware targets over 180 banking, financial services, and cryptocurrency applications across the United States, Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain, and the United Kingdom.
Once installed, OverlayPhantom further conceals its presence by posing as “Google Play Services,” making it exceptionally difficult for average users to detect or remove. From this hidden position, it exploits Android’s Accessibility Service—a feature designed to assist users with disabilities—to gain persistent, high-level control over the compromised device. This access allows threat actors to issue more than 30 remote commands, enabling them to manipulate the device unnoticed by the victim.
The extensive geographical reach and the technical sophistication of OverlayPhantom suggest a well-resourced, financially motivated group orchestrating a large-scale fraud operation. With a target list encompassing over 180 applications and victims spread across major Western markets, OverlayPhantom represents a substantial and ongoing threat.
How OverlayPhantom Operates
The abuse of Android’s Accessibility Service is central to OverlayPhantom’s operational power. After a victim is lured into granting this critical permission—often guided by a deceptive tutorial embedded within the dropper app—the malware establishes a connection to its Command and Control (C&C) server, located at IP address 199.217[.]99[.]122.
The C&C communication is segmented across three distinct ports, enhancing reliability and evasion. Port 9091 is utilized for dispatching commands to the infected device, port 9092 handles device status updates, and port 9090 is dedicated to live screen streaming. This multi-port architecture ensures robust and persistent communication. The malware employs Android’s MediaProjection API to stream the victim’s screen in near real-time, using JPEG compression, providing attackers with an immediate visual feed of all on-device activity.
The remote command capabilities of OverlayPhantom are extensive. Attackers can simulate various user inputs, including taps, swipes, and long presses. They can also lock the screen, manipulate clipboard contents, display fraudulent notifications, and launch overlay windows designed to capture sensitive information such as PIN codes or passwords. These comprehensive controls enable threat actors to execute unauthorized financial transactions without the victim’s awareness.

Overlay Attacks Targeting Banking and Cryptocurrency Apps
OverlayPhantom carries a hardcoded list of target applications within its codebase. When a user opens a banking or financial application, the malware covertly checks if the app is on its predefined list. Upon identifying a match, it dynamically retrieves and renders a deceptive HTML phishing page within a WebView layer, superimposing it directly over the legitimate application interface. This counterfeit screen is meticulously designed to appear identical to the authentic application.
Unsuspecting victims then enter their credentials, believing they are logging into their genuine bank or cryptocurrency wallet. This sensitive data is immediately harvested and transmitted to the C&C server, leaving no discernible trace of compromise. This highly effective overlay technique is a primary reason why OverlayPhantom is so potent and challenging for victims to detect.

What You Should Do
- Download Apps Only from Official Stores: Restrict app downloads exclusively to trusted platforms like the Google Play Store. Avoid installing applications from third-party sources or direct links.
- Exercise Caution with Links: Be highly suspicious of links received via SMS, email, or social media, especially those prompting application downloads or system updates.
- Review Accessibility Permissions: Never grant Accessibility Service permissions to any unfamiliar or suspicious application. Understand the implications of such permissions before enabling them.
- Enable Multi-Factor Authentication (MFA): Implement MFA on all banking, financial, and cryptocurrency applications to add a critical layer of security, protecting accounts even if credentials are stolen.
- Keep Software Updated: Regularly update your Android operating system and all installed applications. Security patches frequently address vulnerabilities that malware like OverlayPhantom exploits.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps://bitlrewards-app[.]com/api/download/IDAustria | Distribution URL used to spread OverlayPhantom |
| IP | 199.217[.]99[.]122 | C&C server IP address |
| File Hash (SHA-256) | 9ef37376bfaa18e193cc72218924ad8ebf56d2667d348f0eae5ae6ec45ab8775f | OverlayPhantom malware sample hash |
| File Hash (SHA-256) | 8b614a2918378063d6e6655b676ceb52ae65b1510e2cc08087fcac31acb7aeb8d | OverlayPhantom malware sample hash |
| File Hash (SHA-256) | dc1f2a75f3d5b5bd054a5367bd5015ebc90f3453d63c7cce438c12dc2ae86a | OverlayPhantom malware sample hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.