New DoubleTrouble banking trojan spreads via Discord – so be on your guard
- DoubleTrouble malware is now hosted on Discord
- The malware still poses as a European bank, so users beware
- It comes with screen recording, “advanced” keylogging, and new UI overlay capabilities
Infamous Android banking trojan DoubleTrouble is now being distributed through Discord-hosted APKs, researchers have said, warning users of a “disturbing trend” towards social media platforms being used as delivery channels for malware.
DoubleTrouble is a well-known banking trojan, named for its ability to hinder static analysis by assigning “nonsensical two-word combinations” to its methods and class names.
In its early days, the malware was distributed via spoofed websites of European banks, and contained basic functionalities such as overlays to steal banking credentials, the ability to capture lock screen information, and keylogging.
A growing mobile threat
However, new findings from Zimperium’s zLabs security team claim the malware evolved, not just in its infostealing capabilities, but also in how it is being distributed.
The recently observed variants also come with screen recording, “advanced” keylogging, and new UI overlay capabilities designed to steal credentials and manipulate infected devices.
As for delivery, DoubleTrouble still runs bogus websites, but the malware itself is hosted within Discord channels.
Once the app is installed, it deploys the actual malware in the form of an extension, or an add-on. It also uses the Google Play icon to hide in plain sight and appear trustworthy.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The final step is to ask for Accessibility Services permissions, which grants it the ability to steal all the necessary information. This is also the usual red flag for Android-borne malware and should always raise suspicion with users.
“As attackers shift to mobile-first strategies and use dynamic delivery methods like Discord to evade traditional defenses, organizations need real-time, on-device protection,” said Kern Smith, VP of Solutions Engineering at Zimperium.
“DoubleTrouble is a stark reminder that mobile threats are growing more evasive and more dangerous, targeting everything from banking credentials to cryptocurrency wallets.”
As usual, the best way to defend against this type of attacks is to only download apps from official repositories, and to keep the device protected with Play Protect and Android security solutions.
You might also like
DoubleTrouble malware is now hosted on Discord The malware still poses as a European bank, so users beware It comes with screen recording, “advanced” keylogging, and new UI overlay capabilities Infamous Android banking trojan DoubleTrouble is now being distributed through Discord-hosted APKs, researchers have said, warning users of a “disturbing…
Recent Posts
- LG Promo Codes and Coupons for June 2026
- 30% Off Canon Promo Codes | June 2026
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023