This Famous Android Banking Trojan Now Lets Hackers Control Your Phone Remotely – How to Stay Safe

Jugo Mobile
By
Jugo Mobile
Jugo Mobile is a platform dedicated to high-quality content in gaming, sports, and tech. Engage with high-quality content and connect with fellow enthusiasts and experts. Explore...
8 Min Read

Hackers have a new tool in their arsenal as one of the most advanced Banking Trojans for Android has just been updated with new features that allow you to remotely control infected devices.

First discovered by security company ThreatFabric back in 2021, vulture was one of the first banking trojans that could record the screen of infected Android smartphones. Since then, its creators have updated this Android malware to make it even more dangerous.

As reported by safety week, new technical features have been added to Vultur and the malware is now even better at evading detection as well. Although it was initially distributed using malicious applications on the Google Play Store, security researchers from the NCC Group I recently observed a new campaign that uses a novel distribution method to trick unsuspecting users into installing this malware on the best android phones.

Here’s everything you need to know about the Vultur banking trojan along with some tips and tricks on how to prevent hackers from hijacking your phone.

Infect victims with a hybrid attack

A person holding a phone near a laptop, depicting an article on how to set up a Wi-Fi hotspot on Android

(Image credit: Shutterstock)

Instead of infecting users through malicious apps, this new campaign uses a hybrid attack that begins with a text message and is then followed by a phone call and another text message.

In its report, security researchers at NCC Group explain that this hybrid attack begins with a text message that instructs potential victims to call a number if they did not authorize an important transaction from their bank account. Although this transaction never took place, the message creates a sense of urgency which could be enough to trick users into calling the number.

If they call to ask about the large transaction, a second text message is sent during the call. It contains a link to a trojanized version of a McAfee Security application that you are forced to install on your smartphone. The app itself looks legit at first glance, but it actually contains the Brunhilda dropper which is then used to download the Vultur banking Trojan.

The malware is downloaded in three separate payloads that are combined on the target Android smartphone. Once installed, the hackers behind this campaign gain full control over an infected device.

A more dangerous vulture

A hacker typing quickly on a keyboard.

(Image credit: Shutterstock)

The Vultur banking trojan was quite dangerous when it was first observed, but now it has even more features that hackers can use in their attacks.

For example, malware can download, upload, delete, install and search for files on an infected Android smartphone, but it can also prevent applications from running. Additionally, you can display a custom notification in the status bar and even disable Keyguard, allowing you to bypass the lock screen. However, the new remote control capabilities are by far the most interesting.

Although Vultur still uses AlphaVNC and ngrok for remote access functionality as it did in 2021, a hacker can now send commands to an infected smartphone to perform scrolling, swipe gestures, clicking, muting/unmuting the device, and more.

As with other Android malware strains, Vultur abuses operating system features. Accessibility services to gain even more control over an infected device. The cybercriminals behind this banking Trojan are also taking advantage of Google’s Firebase Cloud Messaging (FCM) service to send messages from a command and control (C2) server that control an infected phone.

Typically, hackers need to have a continuous connection to an infected device in order to control it. However, using FCM, they can send a command even if connection to the device is lost. AlphaVNC and ngrok still require a continuous remote connection, but this new feature adds more flexibility and makes things easier for hackers who have implemented this malware in their attacks.

The newly added file manager functionality also gives hackers more control over infected Android smartphones, as they can remove existing files from the device and upload new ones to use in additional attacks.

How to stay safe from Android malware

A hand holding a phone logging in securely

(Image credit: Google)

Although normally I would recommend that you stay away from Android apps with poor ratings and avoid download applications If you want to stay safe from malware, this campaign is a little different.

It’s more like a phishing attack since it begins with an urgent message from an unknown sender. In cases like this, you should stay calm and avoid letting your emotions get the best of you. Instead of responding to the message immediately or even replying, the first thing you should do is check your bank accounts to see if this large transaction really occurred. This would reveal that this was not the case and you could safely ignore the message.

At the same time, you will never want call back hackers by phone when they provide you with a number, either by text message or email. Automated email security controls now prevent many of your messages from reaching you, which is why hackers have started trying to trick users into calling them. It’s much easier to convince someone to do something they don’t necessarily want to do when you talk to them on the phone.

To protect yourself from Trojanized applications like the one used in this attack, you must ensure that Protect Google Play is installed and enabled on your Android smartphone. However, nowadays most Android phones come pre-installed. For additional protection, you should also consider using one of the the best antivirus apps for Android as they are updated more frequently and many of them include additional security features such as vpn or a password manager.

In an email to Jugo Mobile, a Google spokesperson provided more information about how the search giant is working to keep Android users safe from Vultur malware, saying:

“Android users are automatically protected against known versions of this malware using Google Play Protect, which is enabled by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps that are known to exhibit malicious behavior, even when those apps come from sources outside of Play.”

As Google and other companies improve their ability to defend against attacks like this, hackers will continue to come up with new ways to trick you into installing malware on your smartphone. That is why you should be very careful when installing any new application and avoid at all costs those that you have to install manually.

  • Hackers are using these Android apps on the Play Store to carry out attacks
  • Darcula phishing service targets Android users via RCS
  • The FTC Just Issued a Warning About This Scam Stealing Thousands of Dollars from Americans

Share This Article
Follow:
Jugo Mobile is a platform dedicated to high-quality content in gaming, sports, and tech. Engage with high-quality content and connect with fellow enthusiasts and experts. Explore the latest trends and innovations in our vibrant community. Join us and experience the future today!
Leave a Comment
Grow your brand and reach a larger audience. Advertise with us today and get noticed by thousands.
© 2025 Jugo Mobile. All Rights Reserved.