Last updated: April 29, 2026
Indian users are targeted by mobile banking trojans regularly. Defenders need to understand the patterns.
Common Android malware patterns
- Accessibility service abuse — read screen, autofill credentials, dismiss prompts
- SMS interception — intercept OTPs from banks
- Overlay attacks — display fake login screen on top of legitimate banking app
- Notification listening — read notifications including OTPs
- Device admin abuse — prevent uninstall, factory reset
Analysis workflow
- Static: APK decompile, manifest review, permissions, hardcoded URLs/keys
- Dynamic: install in emulator with Frida; observe behaviour
- Network: TLS-MITM with mitmproxy; map C2 endpoints
- Persistence: device admin, accessibility service, BOOT_COMPLETED receivers
iOS context
iOS malware is rarer (no sideloading on non-jailbroken devices). When it happens (Pegasus-class), it’s nation-state sophistication and harder to analyze.
Module Quiz · 5 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.