Newly discovered Android banking Remote Access Trojan (RAT), dubbed Klopatra, has compromised more than 3,000 devices in Spain and Italy. Security researchers from Cleafy revealed that Klopatra uses hidden Virtual Network Computing (VNC) to give attackers full remote control over infected smartphones.
Klopatra spreads through malicious dropper apps disguised as IPTV streaming tools. Once installed, these apps trick users into granting permissions to install from unknown sources. The trojan then abuses Android accessibility services to read screens, capture keystrokes, and even perform transactions without the user’s knowledge.
The malware goes further by:
What makes Klopatra especially dangerous is its professional-grade code protection. By using tools like Virbox and shifting much of its functionality from Java to native libraries, the malware is harder to detect and analyze.
Klopatra isn’t the first Android trojan, but it signals a worrying trend: threat actors are now using commercial-grade software protection solutions to hide, protect. and extend the lifespan of their malware. This makes the identification, containment, eradication, and remediation of these financial crimes more difficult, time consuming, and costly to society. Combined with the effectiveness of this attack at silently draining bank accounts and we have a highly impactful threat to the world.
Google confirmed that Klopatra has not been found on Google’s Play Store and that Google Play Protect blocks known variants. Consequently, the risk here comes from downloading apps outside official sanctioned and reviewed marketplaces.
With ongoing awareness training, phishing simulations, and dark web monitoring, CyberHoot empowers organizations to turn their users into a powerful first line of defense against these threats.
Our training includes:
Sources and Additional Reading:
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
Newly discovered Android banking Remote Access Trojan (RAT), dubbed Klopatra, has compromised more than 3,000...
Read moreIn June 2025, KNP Logistics Group, a transport company in the UK with 500 trucks and nearly two centuries of...
Read moreVulnerability scanning and it's human led partner penetration testing (aka "pentesting") are excellent and...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.