Exobot Trojan Source Code Sold
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Exobot was first observed in 2016 operating as a malware-as-a-service (MaaS) scheme, with users renting the trojan from it's creator. It is delivered disguised either as a legitimate application or as a download from a website.
Once installed on a device, Exobot attempts to steal financial credentials such as banking logins, and will perform browser injection attacks on banking websites.
Threat updates
| Date | Update |
|---|---|
| 24 Jul 2018 |
Threat updates
Exobot's source code was leaked in May 2018 at which point other malware authors began to integrate it or portions of its code into their own malware. It is highly likely that these malware are now using Exobot's infection chain in order top infect devices running the newest versions of Android. |
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
Last edited: 9 October 2020 1:46 pm