New Android Banking Trojan BlankBot Identified, Poses Significant Risks

04 Aug 2024

BlankBot: A New Android Banking Trojan Threat

Threat intelligence experts have recently identified a new Android banking trojan that poses significant risks to users. Dubbed BlankBot, this malware is adept at capturing SMS text messages, banking credentials, and even device lock patterns or PINs. What sets BlankBot apart is its stealthy nature; it remains undetected by most antivirus software, making it a particularly insidious threat.

The malware was first detected by researchers at Intel 471 on July 24, primarily targeting users in Turkey. Although BlankBot is still believed to be in active development, its capabilities are already alarming. The trojan can perform a variety of malicious actions, including customer injections, keylogging, and screen recording, all while communicating with a control server via a WebSocket connection.

BlankBot Targets Users Of Android 13 And Newer

Currently, BlankBot is distributed through various utility applications aimed at Android users. Its ability to evade detection by most antivirus programs is concerningly familiar to those who have encountered other malware threats. To gain full control over an infected device, BlankBot exploits Android accessibility services.

Upon installation, users are prompted to grant necessary accessibility permissions under the guise of ensuring proper functionality. However, what remains hidden is the absence of an application icon or any visible interface. Instead, users are met with a blank screen that claims an app update is in progress, advising them not to interact with the device. In reality, the trojan is securing permissions in the background and establishing a connection to a malicious control server.

If the device runs on Android 13 or newer, BlankBot employs a session-based package installer that circumvents restricted settings, prompting users to allow installations from third-party sources. This tactic enables the malware to maintain persistence on the device, effectively locking users out of critical settings.

Mitigating BlankBot Infection

While BlankBot is still evolving, researchers emphasize that it can be thwarted by adhering to fundamental security practices. The most crucial advice is to download applications exclusively from official app stores and to avoid side-loading apps, regardless of their allure. Additionally, users should exercise caution when granting permissions, particularly accessibility permissions, which can grant an application extensive control over the device.

It’s essential to question the necessity of such permissions and consider whether alternative applications from reputable sources can provide similar functionality without the associated risks.

I have reached out to Google for a statement.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6676117
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1400196
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
556689
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
461183
downloads

News and reviews for Mobile Android

SmartTube Pulled from Android TVs Over Security Issue

SmartTube was disabled due to a security issue but new versions are available to sideload.

Read more

Best Apps for Mobile Mining in 2025: DeepHash Leads

In 2025, mobile mining apps facilitate BTC, DOGE, and LTC earnings effortlessly, optimizing renewable energy usage and transparent payouts.

Read more

Google Translate Enhanced for Samsung Smart Glasses

Google Translate adds 'Glasses' option for audio playback, enhancing use on Samsung's smart glasses.

Read more

Gemini Enhances Google Maps with Advanced Voice Features

Gemini integrates with Google Maps, enhancing voice capabilities for users on Android and iOS. Rollout began November 2025.

Read more

Microsoft Copilot to Exit WhatsApp by January 2026

WhatsApp's policy update will end Microsoft Copilot on the platform by January 2026, promoting MetaAI instead.

Read more

Google Enhances Circle Search with AI Mode in Beta

Google tests AI Mode for Circle Search with a bottom search bar, aiming to improve usability and interaction. Available in Google app beta.

Read more

Unity Engine Flaw Threatens Android Casino Apps

Disclosed Unity Engine flaw affects Android games. Casino apps face major risks. Immediate actions advised.

Read more

Android Deals: Big Discounts on Popular App Games

Get major discounts on Android games like Final Fantasy, available for a limited time.

Read more

Marvel Rivals Anniversary Event: Free Units and New Modes

Marvel Rivals celebrates an anniversary with free Units and an 18v18 mode, Annihilation, available until 2025-12-18.

Read more

New 'Connected via' Label Causes Confusion on App Store

X's update to show device usage in the App Store label sparks confusion among Android users.

Read more