Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
New Bank Trojan Infecting Thousands of Android Devices, Capable of Draining Accounts Automatically, Warns Cleafy

New Bank Trojan Infecting Thousands of Android Devices, Capable of Draining Accounts Automatically, Warns Cleafy

Daily HodlDaily Hodl2025/10/11 16:00
By:by Henry Kanapi

A newly discovered Android banking trojan is giving hackers the ability to hijack mobile devices and drain accounts while victims sleep.

In a new report, Italian cybersecurity firm Cleafy says the malware, named Klopatra, has already infected more than 3,000 devices across Europe in active campaigns targeting banks in Spain and Italy.

Cybersecurity researchers say the threat surfaced in late August 2025 and represents a “significant evolution in mobile malware sophistication.” Klopatra combines full device takeover with next-level code obfuscation designed to block detection and traditional analysis methods.

According to Cleafy, Klopatra infects devices by posing as a legitimate app called Mobdro Pro IP TV + VPN. The app promises access to high-quality television channels, which researchers say is a design choice, as users are willing to install pirated streaming apps from unofficial sources to bypass the Google Play Store.

Once installed and permission is granted, Klopatra abuses Android’s Accessibility Services to read screen content, capture keystrokes and simulate taps to approve fraudulent bank transfers.

“It can simulate taps and gestures, allowing it to navigate apps, click buttons (‘Allow,’ ‘Transfer’), enter text, and ultimately, perform fraudulent transactions autonomously.

The abuse of Accessibility Services is the cornerstone of modern banking malware fraud. The technical mechanism turns a malware infection into a direct financial loss, allowing Klopatra to operate with the same level of authority as the legitimate user, but completely invisibly.”

Cleafy warns that the attackers often strike at night when victims’ phones are charging and unattended, using stolen unlock patterns or PINs to quietly execute instant bank transfers.

“Klopatra represents a significant and sophisticated threat to the financial sector and mobile device users, particularly in Europe. The analysis conducted by the Cleafy team revealed malware that is not only technically advanced but is also managed by a cohesive and disciplined Turkish-speaking criminal group, controlling operations from A to Z.”

Generated Image: Midjourney

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!