Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Location-Based Gaming NFTs: How GPS and Blockchain Are Changing the Way We Play

May 2, 2026

ZachXBT Exposes US Law Firm Gerstein Harrow’s $71M Grab of Stolen Lazarus Funds

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Xenomorph Malware Resurfaces: 30+ US Banks Targeted
Xenomorph Malware Resurfaces: 30+ US Banks Targeted
Security

Xenomorph Malware Resurfaces: 30+ US Banks Targeted

September 26, 2023No Comments2 Mins Read

Xenomorph malware has reemerged in a new distribution campaign, expanding its scope to target over 30 US banks along with various financial institutions worldwide. 

Cybersecurity analysts from ThreatFabric recently uncovered this resurgence, which relies on deceptive phishing webpages posing as a Chrome update to trick victims into downloading malicious APKs.

Xenomorph first came to the attention of experts in February 2022. This malware is known for using overlays to capture personally identifiable information (PII) such as usernames and passwords. Notably, it features a sophisticated automated transfer system (ATS) engine, enabling a wide range of actions and modules, enhancing its adaptability.

The latest campaign has seen a geographical expansion, with thousands of Xenomorph downloads recorded in Spain and the United States, reflecting a broader trend among malware families to target new markets across the Atlantic.

In technical terms, Xenomorph has added new capabilities to its arsenal, including an anti-sleep feature, a “mimic” mode to avoid detection and the ability to simulate touch actions. The malware’s targets include Spain, Portugal, Italy, Canada, Belgium, numerous US financial institutions and cryptocurrency wallets.

Read more on Xenomorph: Hadoken Security Group Upgrades Xenomorph Mobile Malware

Another noteworthy development is the observation of Xenomorph being distributed alongside powerful desktop stealers, raising questions about potential connections between threat actors behind these malware variants, or the possibility that Xenomorph is now being offered as a Malware-as-a-Service (MaaS) for use in conjunction with other malicious software families.

According to an advisory published by ThreatFabric on Monday, this resurgence underscores the persistent efforts of cyber-criminals to maximize their profits.

“Xenomorph, after months of hiatus, is back, and this time with distribution campaigns targeting some regions that have been historically of interest for this family,” reads the technical write-up.

See also  North Korean IT workers operated within DeFi protocols for years, researcher warns

“Xenomorph maintains its status as an extremely dangerous Android Banking malware, featuring a very versatile and powerful ATS engine, with multiple modules already created, with the idea of supporting multiple manufacturer’s devices.”

The ThreatFabric advisory, includes a detailed appendix with crucial information for identifying infections related to the Xenomorph malware.

Editorial image credit: HI_Pictures / Shutterstock.com

Source link

Banks Malware Resurfaces Targeted Xenomorph

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

What does Lido’s targeted rsETH fix mean for LDO and EarnETH holders?

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026
Top Posts

Morgan Stanley enters bitcoin ETF race with market-leading low fee

March 27, 2026

Trump Crosses Iran’s ‘Red Line’ By Heavy Bombing Of Kharg Island, Endangering Energy Assets Across Region

March 14, 2026

Developers Issue Statement on Major Altcoin Hack

April 2, 2026

Type above and press Enter to search. Press Esc to cancel.