OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and Crypto Apps (Cyble CRIL)
OverlayPhantom Android Banking Trojan (TL-2026-0598) is a critical-severity malware campaign, first published 2026-05-27. It has no confirmed attribution, affects Google Android, maps to 21 MITRE ATT&CK techniques (T1406, T1414, T1417.002), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-0598
- Threat ID
- TL-2026-0598
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-05-27
- Last reviewed
- 2026-05-27
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- financial-services, banking, cryptocurrency, consumer, government
- Target regions
- North America, Europe, Oceania
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in OverlayPhantom Android Banking Trojan
Malware and tooling: OverlayPhantom, OverlayPhantom custom TCP socket C2 (ports 9090/9091/9092)
OverlayPhantom is a previously undocumented Android banking trojan disclosed by Cyble Research and Intelligence Labs (CRIL) in May 2026 and active in the wild since May 2025. It is distributed via malicious URLs impersonating ID Austria and TikTok, abuses Android Accessibility Services to drive overlay phishing, JPEG screen streaming, and remote gesture automation, and targets 180+ banking, financial, and cryptocurrency applications across 10 Western nations. Its single C2 (199.217.99.122) uses dedicated TCP ports 9090/9091/9092 for streaming, command, and status channels respectively.
How OverlayPhantom Android Banking Trojan works
OverlayPhantom is a financially motivated Android banking trojan first observed in early May 2025 and publicly disclosed by Cyble Research and Intelligence Labs (CRIL) on 27 May 2026. The malware family is characterized by Cyble as 'previously undocumented' with no published code or infrastructure overlap with established Android banking trojan families such as Cerberus, Hydra, ERMAC, Anatsa, BrasDex, Sharkbot, Hook, or GodFather. The threat actor is unattributed but described as having both the technical capability and strategic intent to conduct large-scale financial fraud across Western markets.
Distribution and Two-Stage Infection Chain. The campaign is delivered through phishing URLs serving counterfeit application installers. The first observed sample impersonated 'ID Austria' — the official Austrian government digital identity application — and was served from hxxps://bitlrewards-app[.]com/api/download/IDAustria. A second wave impersonated TikTok and targeted Spanish users. The dropper APK launches a convincing fake Google Play update screen and walks the victim through an interactive step-by-step tutorial that coerces enabling of the Accessibility Service. After installation, the OverlayPhantom core payload masquerades as 'Google Play Services', hides or renames its icon, and immediately solicits Accessibility permissions. Once granted, the payload establishes a socket-based session with its C2 server at 199.217.99.122.
C2 Architecture. OverlayPhantom uses three dedicated non-standard TCP ports on a single hardcoded C2 IP. Port 9090 carries JPEG-encoded screen streams produced via the Android MediaProjection API and a VirtualDisplay named jpeg-stream, with frames resized to 540px width and dynamic height. Port 9091 carries the bidirectional command channel — operator commands inbound, status and harvested data outbound. Port 9092 is reserved for device status and reporting. Before streaming begins, the malware registers a bot/session identifier derived from its configured Bot ID and the device ID. Streaming is resilient: on socket failure the malware sleeps roughly two seconds and retries, tearing down and re-establishing the socket; repeated failures disable the streaming flag rather than crashing.
Command Set and Capabilities. The malware exposes a 30-command surface. Gesture automation primitives — tap, doubleTap, longPress, swipe, draw — drive arbitrary UI manipulation via Accessibility, enabling on-device transaction authorization. UI-control commands openRecents, switchScreen, volumeUp, volumeDown, power, brightSettings, back, and home navigate the device. The buf command sets attacker-supplied text into the clipboard; notif renders a fake notification banner using the target app's icon and name. switchOffScreen, blankScreen, and blankScreenRm lock the device or display a black overlay to mask on-device fraudulent activity from the victim. pinj displays a credential-collection overlay window for PINs, passwords, or pattern locks. startStreamJpeg/stopStreamJpeg control screen streaming; startStreamACNode/stopStreamACNode exfiltrate the Accessibility UI tree. target receives the active target package list; resendInj and rmResend manage the per-target injection ruleset. ping/Pong maintain the keepalive. register binds a fresh device to a Bot ID. Counterfeit HTML phishing pages are embedded in APK resources and rendered as overlays through WebView when the foreground app matches the hardcoded target list.
Targeting. The malware ships a hardcoded list of more than 180 banking, financial-services, and cryptocurrency applications and is geofenced to 10 countries: United States, Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain, and the United Kingdom. Cyble did not publish the per-package target list in prose form; the full inventory is shown only in Figure 5 of the report.
Evasion and Persistence. OverlayPhantom hides its launcher icon (T1628.001), masquerades as Google Play Services (T1655.001), and uses obfuscated strings (T1406). Persistence is anchored on continuous Accessibility-driven foreground monitoring and a broadcast receiver registered for screen capture (T1624.001). The two-stage dropper-plus-payload delivery limits analytic surface on the initial install.
Defenders should treat 199.217.99.122 and bitlrewards-app[.]com as high-confidence indicators of OverlayPhantom activity, block the three C2 ports at egress, hunt for Accessibility-enable events tied to apps masquerading as Google Play Services, and monitor MediaProjection start events from non-Google-signed packages.
MITRE ATT&CK techniques used in TL-2026-0598
Defense Evasion
T1406 Obfuscated Files or Information; T1516 Input Injection; T1628.001 Hide Artifacts: Suppress Application Icon; T1655.001 Masquerading: Match Legitimate Name or Location
Credential Access
T1414 Clipboard Data; T1417.002 Input Capture: GUI Input Capture; T1453 Abuse Accessibility Features
Discovery
T1418 Software Discovery; T1426 System Information Discovery
Command and Control
T1437 Application Layer Protocol; T1509 Non-Standard Port; T1644 Out of Band Data
Initial Access
T1476 Deliver Malicious App via Other Means; T1660 Phishing
Collection
T1513 Screen Capture; T1533 Data from Local System
Persistence
T1541 Foreground Persistence; T1624.001 Event Triggered Execution: Broadcast Receivers
Execution
Impact
Exfiltration
Affected products and versions in OverlayPhantom Android Banking Trojan
- Google — Android
Vulnerable versions: Android versions where users can grant Accessibility Service permission to sideloaded applications - Multiple — Banking, financial services, and cryptocurrency applications (180+ apps)
Vulnerable versions: Banking and crypto apps relying on knowledge-factor authentication (PIN, password, pattern, SMS OTP) without strong on-device anti-overlay or attestation controls
Remediation for OverlayPhantom Android Banking Trojan
Patches
- No vendor patch — this is malware, not a vulnerability. Ensure devices run Android 13+ with Google Play Protect enabled and current Google Play Services. Android 13 restricted Accessibility access for sideloaded apps; Android 14 hardened the restricted-settings flow — keep devices upgraded.
Immediate actions
- Block C2 IP 199.217.99.122 at perimeter and egress firewalls — drop traffic on TCP/9090, TCP/9091, and TCP/9092
- Sinkhole or block the distribution domain bitlrewards-app[.]com at DNS and web-filtering layers
- Blocklist the three OverlayPhantom SHA256 hashes in mobile EDR, MTD, and EMM/MDM solutions
- Push an emergency advisory to employees and customers warning against installing ID Austria or TikTok APKs delivered via SMS, email, or social-media links — direct users only to official Google Play Store listings
- For Android fleet devices, enforce Google Play Protect and disallow installation from unknown sources via EMM policy
- Hunt EDR/MTD telemetry for Accessibility-enable events on packages masquerading as 'Google Play Services' or signed by non-Google certificates
Workarounds
- Disable installation from unknown sources globally via EMM/MDM
- Audit all apps holding Accessibility privileges on managed devices and revoke from any unrecognized package
- If compromise suspected: revoke Accessibility from the offending app, uninstall via Settings > Apps (some variants block uninstall via gesture interception — boot into Safe Mode if needed), rotate all banking, brokerage, and crypto credentials, contact financial institutions, and consider factory reset
Longer-term hardening
- Deploy mobile threat defense (MTD) or EDR for Android with detection for Accessibility Service abuse, MediaProjection misuse, and overlay window creation by non-system apps
- Enforce Play Integrity API attestation in critical banking, brokerage, and crypto apps to detect rooted, rooted-bypass, or instrumented devices
- Adopt FIDO2/passkey authentication for banking and crypto apps to neutralize overlay credential-theft, SMS OTP interception, and on-device transaction-approval automation
- For banking and fintech operators, implement transaction-level behavioral analytics (typing cadence, touch dynamics, navigation patterns) to detect Accessibility-driven gesture automation
- Restrict installation of apps requesting BIND_ACCESSIBILITY_SERVICE permission from sources outside the Google Play Store via EMM
- Educate users on recognising fake 'Google Play update' prompts and Accessibility setup tutorials
Timeline of OverlayPhantom Android Banking Trojan
- OverlayPhantom first observed active in the wild per Cyble CRIL retrospective analysis — earliest known samples date to early May 2025.
- First documented distribution wave impersonates the official Austrian government digital identity application 'ID Austria', served from hxxps://bitlrewards-app[.]com/api/download/IDAustria.
- Second observed campaign wave impersonates TikTok and shifts geographic focus to Spanish users.
- Hardcoded target list expands to encompass more than 180 banking, financial-services, and cryptocurrency applications across 10 Western nations.
- Threadlinqs Intelligence ingests OverlayPhantom as TL-2026-0598; Researcher publishes D1 record, Detector authors SPL/KQL/Sigma rules, Pentester authors Atomic-style overlay/Accessibility simulations.
- Cyble Research and Intelligence Labs (CRIL) publicly discloses OverlayPhantom in 'OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight', publishing C2 IP, three TCP ports, three SHA256 hashes, the 30-command set, and full MITRE ATT&CK for Mobile mapping.
- As of 2026-05-29, OverlayPhantom remains an active Android banking trojan: Cyble CRIL disclosed it only on 2026-05-27, it has run in the wild since May 2025 targeting 180+ banking/crypto apps, and no takedown, sinkhole, arrest, or attribution has occurred. Its C2 (199.217.99.122) is reported operational and researchers warn the campaign may keep expanding.
Sources cited for OverlayPhantom Android Banking Trojan
- OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight
- Cyble Research and Intelligence Labs Blog Feed
- MITRE ATT&CK for Mobile — T1660 Phishing
- MITRE ATT&CK for Mobile — T1655.001 Masquerading: Match Legitimate Name or Location
- MITRE ATT&CK for Mobile — T1628.001 Hide Artifacts: Suppress Application Icon
- MITRE ATT&CK for Mobile — T1453 Abuse Accessibility Features
- MITRE ATT&CK for Mobile — T1513 Screen Capture
- Android Developers — MediaProjection API
Threats related to OverlayPhantom Android Banking Trojan
- TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users in France, Italy, and Austria
- Copybara Android RAT Delivered via Fake N26 Support Vishing Calls
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play
- Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking Data
- ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries
- Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader
Detection coverage for TL-2026-0598
As of 2026-05-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0598 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.