New DoubleTrouble banking trojan spreads via Discord – so be on your guard
- DoubleTrouble malware is now hosted on Discord
- The malware still poses as a European bank, so users beware
- It comes with screen recording, “advanced” keylogging, and new UI overlay capabilities
Infamous Android banking trojan DoubleTrouble is now being distributed through Discord-hosted APKs, researchers have said, warning users of a “disturbing trend” towards social media platforms being used as delivery channels for malware.
DoubleTrouble is a well-known banking trojan, named for its ability to hinder static analysis by assigning “nonsensical two-word combinations” to its methods and class names.
In its early days, the malware was distributed via spoofed websites of European banks, and contained basic functionalities such as overlays to steal banking credentials, the ability to capture lock screen information, and keylogging.
A growing mobile threat
However, new findings from Zimperium’s zLabs security team claim the malware evolved, not just in its infostealing capabilities, but also in how it is being distributed.
The recently observed variants also come with screen recording, “advanced” keylogging, and new UI overlay capabilities designed to steal credentials and manipulate infected devices.
As for delivery, DoubleTrouble still runs bogus websites, but the malware itself is hosted within Discord channels.
Once the app is installed, it deploys the actual malware in the form of an extension, or an add-on. It also uses the Google Play icon to hide in plain sight and appear trustworthy.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The final step is to ask for Accessibility Services permissions, which grants it the ability to steal all the necessary information. This is also the usual red flag for Android-borne malware and should always raise suspicion with users.
“As attackers shift to mobile-first strategies and use dynamic delivery methods like Discord to evade traditional defenses, organizations need real-time, on-device protection,” said Kern Smith, VP of Solutions Engineering at Zimperium.
“DoubleTrouble is a stark reminder that mobile threats are growing more evasive and more dangerous, targeting everything from banking credentials to cryptocurrency wallets.”
As usual, the best way to defend against this type of attacks is to only download apps from official repositories, and to keep the device protected with Play Protect and Android security solutions.
You might also like
DoubleTrouble malware is now hosted on Discord The malware still poses as a European bank, so users beware It comes with screen recording, “advanced” keylogging, and new UI overlay capabilities Infamous Android banking trojan DoubleTrouble is now being distributed through Discord-hosted APKs, researchers have said, warning users of a “disturbing…
Recent Posts
- The White House is making arcade games racist
- Google patches multiple browser bugs including one that was under active exploitation — so update now
- I tried these stylish, futuristic-looking open earbuds, and although they boast sound by Bose, they’re not as harsh on your wallet — here’s everything you need to know
- OpenAI warns about how good Astra model is at cracking cybersecurity, releases it anyway because it took ‘years of research and big bets’
- GoPro says it’s still committed ‘to your collective stoke’
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023