Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
147
Global rank
181 infographic chevron month
Month rank
173 infographic chevron week
Week rank
0
IOCs

Octo malware, also known as ExobotCompact or Coper, is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot. It poses a significant threat to financial institutions, mobile users, and enterprise networks.

Trojan
Type
Unknown
Origin
1 February, 2021
First seen
6 May, 2026
Last seen
Also known as
ExobotCompact
Coper

How to analyze Octo with ANY.RUN

Type
Unknown
Origin
1 February, 2021
First seen
6 May, 2026
Last seen

IOCs

IP addresses
142.251.154.119
54.146.6.253
142.251.127.81
142.251.14.94
142.251.155.119
216.239.35.0
142.251.14.101
142.251.127.102
208.95.112.1
142.251.150.119
142.251.110.94
142.251.151.119
34.104.35.123
192.178.183.94
216.239.35.8
142.251.127.94
142.251.127.84
176.123.1.132
142.251.20.94
94.74.182.52
Hashes
1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
3b9d18d5cc3af6c0cb3e903327ae3da35634c7c3a0b11413b9a3b1c10c640d5e
5d0432a63d41db7e3ddb6a029b4ab0e24d6716f4bd284a3f1b444c555f389f3c
b4dadf3553bb82499c4d0b6be96c47c46abc6904b611376d75c844ffb83725c6
f0c8c7212edd8e3ba882c549a0b7b2db8c008da65f95bc9a0387b49db61b73c4
906561806d07adf4e0bcb0859ca3f891655daff98decb925cc1f7093f3451887
9febf0f46fefd0bdb3919ecd86376f42058125faf4cf9fc0336aba00729c51ac
ddae559eb07f21484d18179ae5b147495f407dbdc915b028671b3fefa4d7ae7b
23b959347dde59ce4ef495165a390f113744ab870c3e084e579c205f611b4ea6
9a05f8d9b8ef18723c5b80e19c78b223cf7c0576dbfaba8254045fa10fd04646
7ef897a705a501e4721513fd836e8d6cca8ee2cbf4cd98b6681218e8c847a4ef
7954827f139015539f565db4fe377ef8e7f1abfcb7184d69353bd97f80a53099
e80841bc93536d72824e324586383005869d721b6e0824efcc9da9b28382fc9b
f816d2793bf45a827aab6e2d1791db78607814594719fdb5174ba4d8a7d650ab
ccb1be1defddbe8c609c25935515ec3fcb6b58aa5a80248ccdc29fb77ed50d4b
bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
8e89bbb65cdd9fffc294660ba897eb044424a9f80306f1f1f165aeea01d9b8ec
Domains
www.ip-api.com
staging-remoteprovisioning.sandbox.googleapis.com
clientservices.googleapis.com
google.com
time.android.com
thhausgajk.com
connectivitycheck.gstatic.com
update.googleapis.com
www.google.com
edgedl.me.gvt1.com
play.google.com
tunnel.googlezip.net
54623b606ada1211f9813c0c4d18f2a5f.com
content-autofill.googleapis.com
www.gstatic.com
clients2.google.com
www.googleadservices.com
dns-tunnel-check.googlezip.net
accounts.google.com
344d23b6606asd1211f9813c0c4d18f2a5f.com
URLs
http://www.ip-api.com/json
https://thhausgajk.com/mwnhmji2otkynja3/
https://thhausgajk.com/mwnhmji2otkynja3/?language=en&model=samsung+galaxy_s9&is_xiaomi=0&is_samsung=1&app=bawag%20psk%20security
http://connectivitycheck.gstatic.com/generate_204
http://www.google.com/gen_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://clientservices.googleapis.com/chrome-variations/seed?osname=android_webview&milestone=137
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabnf189csbilstywbvahcows7ctwi3wpfruzs=&request_id=d17110e9-14e7-4114-bfa2-630b22663b5d
https://update.googleapis.com/service/update2/json?cup2key=15:luiool8oxfs7f0hlrj-bp98aglovoiulxng7yacoemi&cup2hreq=9a05f8d9b8ef18723c5b80e19c78b223cf7c0576dbfaba8254045fa10fd04646
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabnwfqssabilsty3aw06xqqtiwr8a5cr5q4xe=&request_id=0f1b02dd-b5f1-4d55-87fe-4b05782dbf43
https://update.googleapis.com/service/update2/json?cup2key=15:iu7gfyxlxlzdetlecelzfp7fvtyo1t7k8dxapcjsjfq&cup2hreq=ed0b372e9e958661a5af11af6a862f8d0e7bbb9b776fbb5bf7c897171f992d2c
https://update.googleapis.com/service/update2/json
https://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabnuk64r4bilsty0qqwwcfzufmpito0-jvcbi=&request_id=3405c9c1-9673-4dc9-95ff-e4822d55354a
https://update.googleapis.com/service/update2/json?cup2key=15:na-j7q-_px0ncos0si4rvjcw99hn0grsopb_svc2ngo&cup2hreq=e4bfb6e1cb89eb04d979ddb87f376a662da88e2fed663289a1f58e88e0782aca
https://www.google.com/complete/search?hl=en&client=android&q=b
https://www.google.com/complete/search?hl=en&client=android&q=ba
https://www.google.com/complete/search?hl=en&client=android&q=bak
https://www.google.com/complete/search?hl=en&client=android&q=i
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2227
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6651
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10099
comments 0

What is Octo malware?

Octo, also known as Coper or ExobotCompact, is an Android banking Trojan that evolved from the Exobot malware family, first observed in 2016. Initially based on the Marcher Trojan, Exobot targeted financial institutions globally until 2018, when a lighter version, ExobotCompact, emerged.

By 2021, a new variant appeared, named Coper by some antivirus vendors, but later renamed as Octo — a rebranded and enhanced ExobotCompact. In 2024, Octo2, an even more advanced iteration, was released, driven partly by the leak of Octo’s source code. The Malware-as-a-Service (MaaS) model makes Octo accessible to even novice cybercriminals.

Lineage:

  • Exobot, an Android banking trojan that went inactive, and its source code leaked.
  • ExobotCompact, a more compact version with no dependency on older Android APIs.
  • Octo, enhanced version with powerful remote access and evasion features.
  • Coper is sometimes considered a separate but related strain, circulating in Latin America, sharing infrastructure/code.

Octo’s Distribution

The malware targets Android devices through social engineering and malicious app distribution:

  • Fake Apps and Droppers: Octo disguises itself as legitimate apps like Google Chrome, NordVPN, or banking apps, often using a dropper service called Zombinder to bundle with legitimate APKs. These are typically distributed via third-party app stores, malicious websites, or phishing campaigns, though some droppers.
  • SMS Phishing (Smishing): Messages with malicious links trick users into downloading fake apps posing as WhatsApp, Netflix, or banking services. This functionality is similar to that of Salvador Stealer, another Android banking trojan.
  • Social Engineering: Campaigns often impersonate trusted brands or simulate urgent software updates. Regional targeting, such as fake Bancolombia apps for Colombian users, enhances credibility.

Once installed, Octo prompts users to enable Accessibility Services and give out Device Admin privileges, granting extensive control over the device, and enhances remote access stability.

Its communications with C2 servers include dynamic configurations to target specific apps (e.g., to block push notifications from banking apps).

Octo’s Key Operation Vectors

  • Keylogging: to capture credentials, PINs, and lock patterns. Data is temporarily stored in the device’s data directory before deletion to avoid detection.
  • Overlay Attacks: the trojan displays fake login screens or overlays mimicking banking apps to steal credentials and card details. Overlays adapt dynamically to the active app, increasing deception.
  • SMS and Notification Interception: Intercepts messages and push notifications, enabling attackers to bypass two-factor authentication (2FA).
  • Remote Access (VNC): Uses Android’s MediaProjection for near-real-time screen streaming (1 screenshot per second. Sends live feed to C2, allowing attackers to see everything that happens on the device.
  • Device Takeover: Can simulate clicks and actions in real-time.
  • Ransomware-Like Locking: Some variants (like Coper) can lock screens and demand ransom.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Why Octo Is Especially Dangerous

  • Full Remote Control of Mobile Devices.
  • Live Monitoring and Fraud: Attackers perform fraud while victims are active, bypassing behavioral fraud detection.
  • Two-Factor Authentication Bypass: Through SMS or code-grabbing overlays.
  • Modular Structure: Can load updated components from C2 without user knowing.
  • Enterprise Risk: Can be used as an entry point into corporate networks via compromised employee devices (BYOD); targets banking customers and employees.

Octo’s Execution Process and Evasion Techniques

ANY.RUN’s Interactive Sandbox supports the analysis of APK files and enables the research of Android malware. Let us observe the behavior of an Octo sample where the malware is disguised as Google Chrome browser.

View Octo analysis session in the Sandbox

Once installed, Octo — also known as Coper or ExobotCompact — connects to its command and control (C2) server, potentially using a domain generation algorithm (DGA) to maintain resilient, encrypted communication. In our case, the address was toplamakampiyolculukhazirlik[.]xyz, visible in the DNS requests tab, though unresolved. The C2 provides configuration files and commands specifying which apps to target and what actions to take. In this task, the C2 was already offline.

Octo abuses Android’s Accessibility Service and MediaProjection APIs to gain full remote control, enabling real-time screen streaming, simulated taps, gestures, clipboard access, and text input. To stay hidden, it can display a black screen, dim brightness to zero, and disable notifications.

The malware supports keylogging, SMS and notification interception, blocking app alerts, screen locking/unlocking, muting sound, launching apps, and sending SMS. Attackers use AES-encrypted, Base64-encoded commands to control these features and perform on-device fraud—initiating and confirming transactions without triggering alarms.

Octo sample analysis in ANY.RUN Sandbox Octo mobile trojan analysis in ANY.RUN's Interactive Sandbox

Octo can also inject fake overlays to steal credentials and uninstall competing or security apps to maintain persistence and avoid detection.

This malware employs advanced methods to avoid detection. It requires no root access using Accessibility Services for control. Its small, modular codebase demonstrates a lightweight footprint helping to avoid detection by traditional antiviruses. Besides, obfuscation is applied, along with multi-layered code encryption, dynamic loading of malicious libraries. Continuous updates by developers and forks from the 2024 source code leak keep Octo ahead of traditional detection methods.

Expose malicious activities and get IOCs with ANY.RUN sandbox

  • Analyze malware in Windows 7, 10, and 11 VMs
  • Interact with files and links, just like on your own computer
  • Work in a private team space with your colleagues
Request 14-day free trial

What are the best-known Octo attacks?

While many campaigns are not publicly attributed due to the nature of mobile malware distribution, several have been documented by security vendors and researchers.

Year Campaign / Actor Region Method Targets
2022 Coper (Octo variant) Latin America Fake banking apps, smishing Colombian & Peruvian banks
2022 Octo advertised on dark web Global Malware-as-a-Service (MaaS) European banks
2022 Fake Chrome Update Global Smishing, fake update Generic users, credential theft
2022–23 Google Play fake apps Global Dropper apps Banking and crypto users

Gathering Threat Intelligence on Octo malware

Octo can be detected by such indicators as C2 domains, IPs, and unusual DNS traffic. Among the behavioral indicators, analysts should pay attention to background services that relaunch on boot, the use of Accessibility APIs, and unexpected overlays over banking apps. Its APK signatures include package names often mimicking known apps and typical permissions requests, like SYSTEM_ALERT_WINDOW, BIND_ACCESSIBILITY_SERVICE.

To start gathering actionable data via ANY.RUN's Threat Intelligence Lookup, search for the malware name and its aliases:

threatName:"octo" OR threatName:"exobot*"

Octo search in TI Lookup Add all of the Octo’s names to a single search request

Select and view analysis sessions to collect IOCs, IOBs, view processes, and study the malware’s TTPs to set up detection and response system, to develop prevention and mitigation strategies.

Octo’s malicious process in TI Lookup View malicious processes in detail

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Octo malware (ExobotCompact / Coper) is one of the most advanced mobile threats in circulation, particularly dangerous because it provides real-time remote access and can bypass many layers of authentication and fraud detection. While it mainly targets banking users, its modularity and stealth make it a viable tool for cybercrime groups and potential APT-style attacks against enterprises. Countering Octo demands robust threat intelligence, proactive user education, and strict device security practices.

Start with 50 requests in TI Lookup to collect IOCs on the evolving Android malware

HAVE A LOOK AT

EvilTokens screenshot
EvilTokens
eviltokens
EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.
Read More
Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More
Phorpiex screenshot
Phorpiex
phorpiex
Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More