Current threat intelligence points to a surge in operator-driven mobile banking trojans and industrialized phishing ecosystems aimed squarely at European financial institutions. The Klopatra Android RAT is an emerging threat that has evolved quickly and keeps its targeting focused within Europe.
Primary Active Threats
The following table summarizes the most prominent malware families and services currently targeting European banking organizations:
| Malware/Threat Name | Threat Actor / Origin | Primary Targets | Key Characteristics |
|---|---|---|---|
| Klopatra | Turkish-speaking Group | European Banking Accounts | Uses Hidden VNC (HVNC), Accessibility abuse, and commercial-grade obfuscation (Virbox) to perform real-time, silent fraud. |
| Katz Stealer | Unknown | Italy, Finland, Manufacturing | Information stealer often bundled with or related to PureLog Stealer; targets financial and administrative data. |
| EvilProxy | PhaaS Provider | Global Banking / Crypto | Advanced phishing-as-a-service (PhaaS) that automates AJAX-looping to bypass MFA tokens in real time. |
| Cuckoo Stealer | Unknown | Banking Institutions | Emerging info-stealer targeting retail and financial credentials. |
| VMDetectLoader | Unknown | Banking Institutions | Specialized loader designed to detect virtualized environments before delivering banking payloads. |
Technical Analysis: Klopatra & Operator-Driven Fraud
Klopatra marks a shift toward "hands-on" fraud. Operators often control the trojan directly, and that lets them mimic legitimate user behavior and bypass advanced fraud detection systems.
MITRE ATT&CK Mapping for Klopatra:
| Tactic | Technique ID | Description |
|---|---|---|
| Initial Access | T1444 | Sideloading: Delivered via pirated IPTV droppers (e.g., Mobdro Pro IP TV + VPN) requesting REQUEST_INSTALL_PACKAGES. |
| Persistence | T1624 | Accessibility Service Abuse: Abuses Android Accessibility APIs to capture screens, inject gestures, and prevent app termination. |
| Defense Evasion | T1406 | Obfuscation: Employs commercial-grade Virbox packing and native C/C++ libraries to hide core logic from Java-based analysis. |
| Credential Access | T1411 | Adversary-in-the-Middle (Overlays): Uses dynamic HTML overlays to harvest banking credentials and PINs. |
| Command & Control | T1219 | Remote Access Software (Hidden VNC): Enables a "black screen" mode while the device is charging at night to perform silent transactions via HVNC. |
Vulnerability Landscape (CVEs)
Most banking fraud still relies on social engineering and credential theft. Recent bulletins have also flagged the following CVEs as relevant to the wider financial sector:
CVE-2025-23280, CVE-2025-23330, CVE-2025-54252: All three were identified recently and are often weaponized in delivery chains or infrastructure abuse to help financial malware persist.
Infrastructure Abuse: Threat actors increasingly use legitimate services such as AWS X-Ray for covert C2, and signed UEFI shells help them survive as bootkits, preserving long-term access to compromised financial workstations.
Affected European Jurisdictions
Intelligence reports explicitly mention targeted activity in the following European countries:
- Italy: Target of Katz Stealer and PureLog Stealer campaigns.
- Finland: Target of Katz Stealer and automated financial fraud campaigns.
- Turkey: Identified as a primary hub for the development and operation of the Klopatra botnets, with artifacts indicating vertically integrated operations.
Gain continuous, structured threat intelligence with the Threat Landscape Platform. Start free — no credit card required — or upgrade to Professional for just $49/month.