Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
New Bank Trojan Infecting Thousands of Android Devices, Capable of Draining Accounts Automatically, Warns Cleafy

New Bank Trojan Infecting Thousands of Android Devices, Capable of Draining Accounts Automatically, Warns Cleafy

Daily HodlDaily Hodl2025/10/11 16:00
By:by Henry Kanapi

A newly discovered Android banking trojan is giving hackers the ability to hijack mobile devices and drain accounts while victims sleep.

In a new report, Italian cybersecurity firm Cleafy says the malware, named Klopatra, has already infected more than 3,000 devices across Europe in active campaigns targeting banks in Spain and Italy.

Cybersecurity researchers say the threat surfaced in late August 2025 and represents a “significant evolution in mobile malware sophistication.” Klopatra combines full device takeover with next-level code obfuscation designed to block detection and traditional analysis methods.

According to Cleafy, Klopatra infects devices by posing as a legitimate app called Mobdro Pro IP TV + VPN. The app promises access to high-quality television channels, which researchers say is a design choice, as users are willing to install pirated streaming apps from unofficial sources to bypass the Google Play Store.

Once installed and permission is granted, Klopatra abuses Android’s Accessibility Services to read screen content, capture keystrokes and simulate taps to approve fraudulent bank transfers.

“It can simulate taps and gestures, allowing it to navigate apps, click buttons (‘Allow,’ ‘Transfer’), enter text, and ultimately, perform fraudulent transactions autonomously.

The abuse of Accessibility Services is the cornerstone of modern banking malware fraud. The technical mechanism turns a malware infection into a direct financial loss, allowing Klopatra to operate with the same level of authority as the legitimate user, but completely invisibly.”

Cleafy warns that the attackers often strike at night when victims’ phones are charging and unattended, using stolen unlock patterns or PINs to quietly execute instant bank transfers.

“Klopatra represents a significant and sophisticated threat to the financial sector and mobile device users, particularly in Europe. The analysis conducted by the Cleafy team revealed malware that is not only technically advanced but is also managed by a cohesive and disciplined Turkish-speaking criminal group, controlling operations from A to Z.”

Generated Image: Midjourney

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

AAVE gains 4.1% over the past week as Avail Nexus debuts and cross-chain advancements emerge

- AAVE rose 4.1% in 7 days amid Avail Nexus Mainnet launch, enhancing cross-chain liquidity for DeFi. - Avail's Nexus connects Ethereum , Solana , and EVM chains, enabling unified asset flows across fragmented blockchains. - Aave benefits from modular infrastructure trends, supporting multi-chain operations without compromising security or efficiency. - Despite 1-year 39.84% decline, analysts highlight Aave's strategic position in evolving cross-chain DeFi ecosystems.

Bitget-RWA2025/11/29 05:32

LUNA Rises 0.68% on November 29, 2025 as Short- and Long-Term Results Show Mixed Trends

- LUNA rose 0.68% in 24 hours to $0.0745 on Nov. 29, 2025, but fell 20.45% over 30 days and 82.08% in a year. - Analysts predict continued pressure unless on-chain activity or market sentiment improves, as Terra faces post-2022 collapse challenges. - Macroeconomic trends and bearish crypto sentiment weigh on LUNA, with institutional investors hesitant to re-enter at current valuations. - Market watchers monitor for adoption boosts or protocol upgrades to stabilize LUNA’s volatile, high-risk profile.

Bitget-RWA2025/11/29 05:14
LUNA Rises 0.68% on November 29, 2025 as Short- and Long-Term Results Show Mixed Trends

YFI Gains 1.15% as Market Levels Off Following Month-Long Decline

- YFI rose 1.15% in 24 hours to $4224, showing short-term stabilization amid 10.77% monthly and 47.45% annual declines. - Spirit Blockchain Capital appointed Lewis Bateman as interim CFO after Inder Saini's departure, focusing on blockchain financial infrastructure and tech licensing. - Bitget donated $12M HKD for Hong Kong fire victims, while GeeFi's GEE Token presale hit 80% completion with 700+ investors. - Evercore ISI cut Gemini Space Station's price target to $15 from $30 due to crypto market pressur

Bitget-RWA2025/11/29 05:14
YFI Gains 1.15% as Market Levels Off Following Month-Long Decline