{"id":185050,"date":"2022-03-08T11:37:08","date_gmt":"2022-03-08T10:37:08","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=185050"},"modified":"2025-07-01T20:54:18","modified_gmt":"2025-07-02T03:54:18","slug":"sharkbot-malware-android","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/sharkbot-malware-android\/","title":{"rendered":"SharkBot Banking malware masquerades as Android antivirus app"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Malware analysts have uncovered a <strong>threat actor<\/strong> behind a particularly nasty Android banking app trojan named SharkBot. <strong>SharkBot <\/strong>has evaded <a href=\"https:\/\/google-play-store.en.softonic.com\/android\" target=\"_blank\" rel=\"noreferrer noopener\">Google Play Store<\/a>\u2019s security framework for a while, hiding within the coding of deceptive antivirus apps.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Similar to its contemporaries, TeaBot, Oscorp (UBEL), and FluBot, SharkBot belongs to a virulent category of <strong>financially-centered<\/strong> malicious software designed to gain access to users\u2019 banking information. It is able to achieve this by circumventing complex authentication mechanisms and thus siphon <strong>banking app credentials<\/strong> and initiating financial transfers from infected devices. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SharkBot does, however, have a few key differences to its contemporaries that make it a far more dangerous trojan. While other malicious software like TeaBot requires a live operator to remotely interact with the compromised device, SharkBot is capable of leveraging <strong>Automatic Transfer Systems.<\/strong> This means that it can carry out unauthorized financial transactions without a third party interacting with infected devices.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a recent report, malware analysts at the NCC Group cybersecurity firm said the following: \u2018The ATS features allow the malware to receive a list of events to be simulated, and they will be simulated in order to do the money transfers. Since these features can be used to simulate touches\/clicks and button presses, it can be used to not only automatically transfer money but also install other malicious applications or components.\u2019 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What this means is that once SharkBot has infiltrated a user\u2019s device, it <strong>can virtually do anything<\/strong>. It\u2019s able to record touches and keystrokes, create false overlays to trick you into interacting with it instead of your legitimate apps, and even install other malware without your knowledge.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Four apps have been identified on Google Play as containing the trojan. All four are antivirus apps:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Super Cleaner<\/li><li>Atom Clean-Booster<\/li><li>Alpha Antivirus<\/li><li>Powerful Cleaner<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Combined, these apps have been installed around <strong>57,000<\/strong> times since SharkBot was released.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The worst aspect about this virus being injected into fake antivirus apps is that they\u2019re apps that <strong>antivirus protection<\/strong> is a class of application every Android user should have. So how do you know which antivirus to trust?&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The best precaution is to go with a name you trust. Luckily, antivirus providers like <a href=\"https:\/\/avast.en.softonic.com\/android\" target=\"_blank\" rel=\"noreferrer noopener\">Avast<\/a>, <a href=\"https:\/\/norton-mobile-security.en.softonic.com\/android\" target=\"_blank\" rel=\"noreferrer noopener\">Norton<\/a>, and <a href=\"https:\/\/malwarebytes-anti-malware.en.softonic.com\/android\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"Malwarebytes \">Malwarebytes <\/a>have mobile clients. Android phones also usually come <strong>preloaded<\/strong> with antivirus software, most often <strong>supported by Avast<\/strong>. Why not check out our verdict on the mobile clients of your favorite antivirus providers?<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-xl,f_auto\/p\/04cdb438-96d1-11e6-ac69-00163ed833e7\/1339587476\/malwarebytes-anti-malware-icon.png\" alt=\"Malwarebytes cyberprotection\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Malwarebytes cyberprotection<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/estore.malwarebytes.com\/affiliate.php?ACCOUNT=MALWARQO&AFFILIATE=45974&PATH=http%3A%2F%2Fwww.malwarebytes.com%3FAFFILIATE%3D45974&AFFSRC=article\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">FREE DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--90\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"90\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"9\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\">9<\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-sponsored\" href=\"https:\/\/estore.malwarebytes.com\/affiliate.php?ACCOUNT=MALWARQO&AFFILIATE=45974&PATH=http%3A%2F%2Fwww.malwarebytes.com%3FAFFILIATE%3D45974&AFFSRC=article\" target=\"_blank\" rel=\"noopener noreferrer nofollow\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Malware analysts have uncovered a threat actor behind a particularly nasty Android banking app trojan named SharkBot. SharkBot has evaded Google Play Store\u2019s security framework for a while, hiding within the coding of deceptive antivirus apps.&nbsp; Similar to its contemporaries, TeaBot, Oscorp (UBEL), and FluBot, SharkBot belongs to a virulent category of financially-centered malicious software &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/sharkbot-malware-android\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;SharkBot Banking malware masquerades as Android antivirus app&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9222,"featured_media":185053,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[2421],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-185050","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectiongoogle-play-store"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/185050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9222"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=185050"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/185050\/revisions"}],"predecessor-version":[{"id":324294,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/185050\/revisions\/324294"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/185053"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=185050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=185050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=185050"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=185050"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=185050"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=185050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}