TeaBot Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 26, 2025
Last Seen
April 16, 2026

TeaBot is an Android banking trojan family that targets mobile banking apps to steal credentials, OTPs, and other sensitive data.

Overview

TeaBot is an Android banking trojan family that targets mobile banking apps to steal credentials, OTPs, and other sensitive data. It leverages techniques such as overlay attacks and abuse of accessibility permissions to simulate user actions, exfiltrate information, and facilitate fraudulent transactions, marking it as a persistent and evolving threat in mobile financial fraud.

Related Threat Clusters

Recent Intelligence Reports

  • Malformed Apks As An Anti Analysis Technique Malfixer Tool — www.cleafy.com · April 16, 2026
  • APK Malformation Found in Thousands of Android Malware Samples — Infosecurity-Magazine · April 16, 2026
  • The NFC Relay: How NGate Malware Is Rewriting the Rules of Mobile Banking Fraud — Webpronews · November 26, 2025

CVSS v3.1 Breakdown