OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and Crypto Apps (Cyble CRIL) — Threadlinqs Intelligence
As of 2026-05-30, OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and Crypto Apps (Cyble CRIL) is a critical-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0598 · Severity: CRITICAL · Status: ACTIVE · Category: MALWARE
OverlayPhantom is a previously undocumented Android banking trojan disclosed by Cyble Research and Intelligence Labs (CRIL) in May 2026 and active in the wild since May 2025. It is distributed via
OverlayPhantom is a financially motivated Android banking trojan first observed in early May 2025 and publicly disclosed by Cyble Research and Intelligence Labs (CRIL) on 27 May 2026. The malware family is characterized by Cyble as 'previously undocumented' with no published code or infrastructure overlap with established Android banking trojan families such as Cerberus, Hydra, ERMAC, Anatsa, BrasDex, Sharkbot, Hook, or GodFather. The threat actor is unattributed but described as having both the technical capability and strategic intent to conduct large-scale financial fraud across Western markets.
Distribution and Two-Stage Infection Chain. The campaign is delivered through phishing URLs serving counterfeit application installers. The first observed sample impersonated 'ID Austria' — the official Austrian government digital identity application — and was served from hxxps://bitlrewards-app[.]com/api/download/IDAustria. A second wave impersonated TikTok and targeted Spanish users. The dropper APK launches a convincing fake Google Play update screen and walks the victim through an interactive step-by-step tutorial that coerces enabling of the Accessibility Service. After installation, the OverlayPhantom core payload masquerades as 'Google Play Services', hides or renames its icon, and immediately solicits Accessibility permissions. Once granted, the payload establishes a socket-based session with its C2 server at 199.217.99.122.
C2 Architecture. OverlayPhantom uses three dedicated non-standard TCP ports on a single hardcoded C2 IP. Port 9090 carries JPEG-encoded screen streams produced via the Android MediaProjection API and a VirtualDisplay named jpeg-stream, with frames resized to 540px width and dynamic height. Port 9091 carries the bidirectional command channel — operator commands inbound, status and harvested data outbound. Port 9092 is reserved for device status and reporting. Before streaming begins, the malware registers a bot/session identifier derived from its configured Bot ID and the device ID. Streaming is resilient: on socket failure the malware sleeps roughly two seconds and retries, tearing down and re-establishing the socket; repeated failures disable the streaming flag rather than crashing.
Command Set and Capabilities. The malware exposes a 30-command surface. Gesture automation primitives — tap, doubleTap, longPress, swipe, draw — drive arbitrary UI manipulation via Accessibility, enabling on-device transaction authorization. UI-control commands openRecents, switchScreen, volumeUp, volumeDown, power, brightSettings, back, and home navigate the device. The buf command sets attacker-supplied text into the clipboard; notif renders a fake notification banner using the target app's icon and name. switchOffScreen, blankScreen, and blankScreenRm lock the device or display a black overlay to mask on-device fraudulent activity from the victim. pinj displays a credential-collection overlay window for PINs, passwords, or pattern locks. startStreamJpeg/stopStreamJpeg control screen streaming; startStreamACNode/stopStreamACNode exfiltrate the Accessibility UI tree. target receives the active target package list; resendInj and rmResend manage the per-target injection ruleset. ping/Pong maintain the keepalive. register binds a fresh device to a Bot ID. Counterfeit HTML phishing pages are embedded in APK resources and rendered as overlays through WebView when the foreground app matches the hardcoded target list.
Targeting. The malware ships a hardcoded list of more than 180 banking, financial-services, and cryptocurrency applications and is geofenced to 10 countries: United States, Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain, and the United Kingdom. Cyble did not publish the per-package target list in prose form; the full inventory is shown only in Figure 5 of the report.
Evasion and Persistence. OverlayPhantom hides its launcher icon (T1628.001), masquerades as Google Play Services (T16
Target sectors: financial-services, banking, cryptocurrency, consumer, government
Target regions: North America, Europe, Oceania
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1660, T1476, T1575, T1624.001, T1541, T1628.001, T1406, T1655.001, T1516, T1453