Malware

New Android Banking Trojan 'HydraX' Steals OTP Codes from 200+ Banking Apps

ZimperiumMarch 15, 20262 min read
New Android Banking Trojan 'HydraX' Steals OTP Codes from 200+ Banking Apps

Security analysts at Zimperium identified a sophisticated Android banking trojan targeting customers of 200+ financial institutions. HydraX uses accessibility services to intercept OTP codes and exfiltrate credentials.

Zimperium reports the details above as part of its ongoing coverage in the malware space. The picture is likely to sharpen over the coming days as other researchers weigh in.

For security teams, the practical question is always the same: what changes because of this? Early indicators and behavioural signatures let a SOC detect an infection before it spreads. Feed the reported indicators into your monitoring and hunt for the described behaviour.

Follow the source link below for the full report and any indicators of compromise the original authors have published.

Related articles