Android Trojan OverlayPhantom Targets 180+ Banking and Crypto Apps Across 10 Countries, Cyble Reports

According to cybersecurity firm Cyble, a newly discovered Android trojan called OverlayPhantom has been targeting over 180 banking, financial and cryptocurrency applications across 10 countries since May 2025. The malware is distributed through malicious URLs impersonating trusted apps, including ID Austria and TikTok.

Once installed, OverlayPhantom disguises itself as Google Play Services and abuses Android's Accessibility Service to gain device control. The trojan displays fake overlays designed to mimic legitimate applications, capturing usernames, passwords, card details and PINs. Cyble says it can execute over 30 remote commands, conduct real-time screen streaming and exfiltrate harvested credentials. Affected countries include the United States, Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain and the United Kingdom.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments