Klopatra two-campaign Android banking operation
Campaign
Summary
Hide ▲
Show ▼
The Klopatra operation now stands out as a two-campaign mobile banking-theft effort tied to 3,000 unique infections across Europe. That scale matters because the malware combines credential theft with hidden VNC hands-on control, increasing the risk of fraudulent account access and device abuse. The activity has been active since March 2025 and continues to evolve quickly.
Related Happenings
Mirax social media ad campaign targeting Spanish-speaking users
Campaign
H score44
First: 13.04.2026 17:30
Last: 13.04.2026 17:30
Sources 1
About this happening:
The Mirax distribution campaign is using social media advertisements and fake IPTV or streaming apps to reach Spanish-speaking users at scale, raising the risk of...
Mirax social media ad campaign targeting Spanish-speaking users
CampaignAbout this happening: The Mirax distribution campaign is using social media advertisements and fake IPTV or streaming apps to reach Spanish-speaking users at scale, raising the risk of...
Mirax Android banking trojan with residential proxy nodes
Malware Activity
H score37
First: 13.04.2026 17:30
Last: 13.04.2026 17:30
Sources 1
About this happening:
Mirax is spreading across Europe with remote access and residential proxy features, increasing the risk of device compromise, data theft, and traffic abuse. The Androi...
Mirax Android banking trojan with residential proxy nodes
Malware ActivityAbout this happening: Mirax is spreading across Europe with remote access and residential proxy features, increasing the risk of device compromise, data theft, and traffic abuse. The Androi...
Massiv fake IPTV SMS-phishing campaign
Campaign
H score32
First: 19.02.2026 12:24
Last: 19.02.2026 12:24
Sources 1
About this happening:
The Massiv distribution campaign is using SMS phishing and fake IPTV apps to deliver Android malware, creating a direct path to mobile banking theft and device t...
Massiv fake IPTV SMS-phishing campaign
CampaignAbout this happening: The Massiv distribution campaign is using SMS phishing and fake IPTV apps to deliver Android malware, creating a direct path to mobile banking theft and device t...
Massiv Android trojan device-takeover and credential-theft activity
Malware Activity
H score29
First: 19.02.2026 12:24
Last: 19.02.2026 12:24
Sources 1
About this happening:
The Massiv Android trojan has been disclosed as a device-takeover threat that can steal banking credentials and enable fraudulent transactions. It uses screen streaming*...
Massiv Android trojan device-takeover and credential-theft activity
Malware ActivityAbout this happening: The Massiv Android trojan has been disclosed as a device-takeover threat that can steal banking credentials and enable fraudulent transactions. It uses screen streaming*...
Massiv Android banking malware disguised as IPTV app
Malware Activity
H score27
First: 19.02.2026 12:00
Last: 19.02.2026 12:00
Sources 1
About this happening:
The Massiv Android banking malware is posing as an IPTV app to steal digital identities and access online banking accounts. It uses screen overlays, keylogging...
Massiv Android banking malware disguised as IPTV app
Malware ActivityAbout this happening: The Massiv Android banking malware is posing as an IPTV app to steal digital identities and access online banking accounts. It uses screen overlays, keylogging...
Timeline
-
01.10.2025 21:33 2 articles · 9mo ago
Cleafy discloses Klopatra Android banking trojan
Initial DisclosureCleafy identifies Klopatra as a new Android banking and remote access trojan disguised as Modpro IP TV + VPN and says it has infected more than 3,000 unique devices across Europe. The malware abuses Android’s Accessibility service, uses a hidden VNC mode to capture inputs and drain accounts, and researchers assess that it is operated by a Turkish-speaking cybercrime group; the campaign has been evolving since March 2025 and now spans 40 distinct builds.
Show sources
- Android malware uses VNC to give attackers hands-on access — www.bleepingcomputer.com — 01.10.2025 21:33
- Android malware uses VNC to give attackers hands-on access — www.bleepingcomputer.com — 01.10.2025 21:33