OverlayPhantom Android Banking Trojan Targets 180+ Financial Apps Across 10 Countries

OverlayPhantom Uses Trusted Brands to Infect Victims
The initial OverlayPhantom sample was discovered on a malicious domain distributing a fake version of ID Austria, the Austrian government’s official digital identity application. Researchers noted that the use of a government-themed lure increased the effectiveness of the malware campaign because victims are more likely to trust requests tied to identity verification or public services. A second sample linked to the same threat actor impersonated TikTok and appeared to focus on users in Spain. The shift from a government application to a mainstream social media platform suggested that the operators behind OverlayPhantom are deliberately broadening their infection strategies to target both institutional trust and consumer familiarity. CRIL researchers stated that the Android banking trojan employs a two-stage infection process. Victims initially download a dropper application that displays what appears to be a legitimate Google Play update screen. The fake update interface is designed to reduce suspicion and persuade users to continue the installation process. The malware also includes a guided tutorial that instructs victims on how to enable Android Accessibility Service permissions — a critical step that grants the threat actor elevated access to the infected device.Android Banking Trojan Abuses Accessibility Services
Once installed, OverlayPhantom disguises itself as “Google Play Services,” making the malicious application harder for users to detect or remove. Researchers said the Android banking trojan abuses Android’s Accessibility Service to monitor user activity, intercept inputs, simulate gestures, and maintain persistent device control. The malware establishes communication with its command-and-control (C&C) infrastructure through the IP address hxxps://199.217[.]99[.]122 using three separate ports dedicated to different tasks:- Port 9092 handles device status reporting
- Port 9091 is used for command-and-control communication
- Port 9090 supports screen streaming functionality