BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

HOOK Android Trojan Adds Ransomware Overlay, Expands Threats

HOOK Android Trojan Evolves With Ransomware Tactics, Expands Remote Control to Target Financial Apps

  • Researchers have discovered a new version of the HOOK Android banking trojan with Ransomware-like capabilities.
  • HOOK uses full-screen overlays to extort victims and gathers sensitive data using advanced techniques.
  • The Malware can now execute 107 remote commands, including 38 newly added features.
  • HOOK is distributed via phishing websites and fake GitHub repositories with malicious APK files.
  • Other Android threats, such as Anatsa, Joker, and Harly, continue to evolve and target financial applications.

Cybersecurity researchers have identified a new version of the HOOK Android banking trojan, released in August 2025, which now uses ransomware-style screens to demand payments from victims. The trojan displays full-screen warning messages and provides a crypto wallet address and payment amount, both controlled remotely by the attacker.

- Advertisement -

According to experts from Zimperium, HOOK activates these overlays through commands sent from its command-and-control (C2) server, such as the “ransome” command to show the message and “delete_ransome” to remove it. Researchers reported that HOOK evolved from the ERMAC trojan after its source code became publicly available.

HOOK can show fake screens atop financial apps to steal login credentials. It also exploits Android’s accessibility services to automate device control and commit fraud. “A prominent characteristic of the latest variant is its capacity to deploy a full-screen ransomware overlay, which aims to coerce the victim into remitting a ransom payment,” said Vishnu Pratapagiri of Zimperium zLabs in a recent analysis.

This new variant has expanded support to 107 remote commands—up from previous versions—including commands to capture screen gestures, show fake NFC overlays to steal card data, and collect lockscreen PINs or patterns by imitating device prompts. HOOK can also send SMS messages, stream the device screen, take photos using the front camera, and steal cookies and recovery phrases tied to cryptocurrency wallets.

HOOK and similar Android threats are distributed on a wide scale, mainly through phishing sites and fake repositories on GitHub, where victims are tricked into downloading harmful APK files. Other malware families, including ERMAC and Brokewell, use similar delivery tactics.

- Advertisement -

Additionally, Zscaler researchers highlighted ongoing advancements of the Anatsa banking trojan, which now targets over 831 financial and crypto services globally. Malicious apps on the Google Play Store—including document readers and file managers—have been found to drop Anatsa payloads using hidden code in corrupted files. Anatsa, like HOOK, abuses Android’s accessibility services to gain further control over devices.

Researchers also warned that over 77 malicious apps—spanning families like Anatsa, Joker, and Harly—were identified on Google Play, totaling over 19 million installs. Maskware, a term for legitimate-looking apps that hide harmful code, remains a concern, with Harly noted as a major Joker variant.

“Anatsa continues to evolve and improve with anti-analysis techniques to better evade detection,” said Himanshu Sharma of Zscaler in a detailed report. The malware family added over 150 new banking apps to its list of targets.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

EU MiCA Deadline Looms as US CBDC Ban Advances

The EU's MiCA licensing deadline on July 1 is pressuring exchanges, with BitGo launching...

Malicious JetBrains Plugins Steal AI Keys

Fifteen malicious plugins on the JetBrains Marketplace have been stealing AI provider API keys...

Vertiv Stock Slumps Under $300, Bernstein Issues $416 Target

Vertiv stock (NYSE: VRT) fell below $300 this week after hitting a yearly high...

Uniswap Surges on $100 Target, Tokenized Stocks Launch

UNI surged 19.8% to $3.63, reaching its highest level in over a month.Standard Chartered...

AI CEOs Join G7 Summit for Diplomacy Talks

CEOs from top AI firms like OpenAI and Anthropic are attending the G7 summit,...

Must Read

How Cryptocurrency Works For Beginners?

Welcome to the world of cryptocurrency! If you're new to this exciting and rapidly evolving landscape, you might feel like Alice in Wonderland, exploring...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading