Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

DoubleTrouble

149
Global rank
195 infographic chevron month
Month rank
188
Week rank

DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.

Trojan
Type
Unknown
Origin
1 June, 2025
First seen
14 May, 2026
Last seen

How to analyze DoubleTrouble with ANY.RUN

Type
Unknown
Origin
1 June, 2025
First seen
14 May, 2026
Last seen

IOCs

IP addresses
149.154.167.99
142.251.127.84
142.251.127.81
142.251.154.119
142.250.154.102
142.251.110.94
192.178.183.94
142.251.14.97
192.178.183.95
142.251.127.92
216.239.35.0
142.251.127.101
142.251.13.138
142.251.13.119
142.251.150.119
142.251.13.139
216.239.34.36
142.251.155.119
142.251.152.119
142.250.154.113
Hashes
c8a25c6e88da3534074b2a689bd128683d1548c24c0b0372530cfae61d81d907
24f6099070e23828c6d2d89bc653e2bb2ace74b769f33ca7def5050e2c361c33
a4b0e4992464a105e8545fc796e3e0a2d769c143f15483988e542b1906e40f78
e495ecad3d59b70a6daf8d8a28691d649f8aa4f60d35321d9150f0f4c03d38ca
f29a09a24bbf97617c0db01f19d01be607857e0bb58117556e90390de4576216
9fe045cf78165009af73afa6da87b3db66e81f02d6468908d9ee85270479af88
c270e5eec4b009ee00aa909324aa56dfd0fb0629278d06c24f238ee42cbdc9a3
d019bc3b764f8ae8001406ac943136cf0d85da5a39a80e7ab9f9825723cd5435
23fad8c3189545275f333cea63af0c86107797fc881ed4dbaca0eb807d906ffe
d101d6b3a9cc0771de2a7e8f28626ace7af17f732001318bd14d4250881d5567
4dc64aab27808486950d9e6be1fa7b6a8b790bc8824ab0e0cd442f0506d0d886
1b790a4b22ce578b6e9dee1831fbdefc334d13b1549baab1cb0231c3fa8b74b8
6f6f526c8d5f85d6dd52064a083eb26236e704d3ddaa06373a4d3d99d57da393
36a9e7f1c95b82ffb99743e0c5c4ce95d83c9a430aac59f84ef3cbfab6145068
502e9680cfa78fa8be779cbf4f1947c8eaa3d43bf8c7464800ec772b2ddea358
317e5fdaa14e548c0045d5e662709cfe0b692e0384a8396cf22054bf0a1e1c48
a11fbbb463461087e3e1522f0e58f0bb1020a54b741cf493dbd6e0ce3923d811
95d4300578446bf713fcf326ded94be0c3dc337a488dad7b1216220c5a099240
b704ce6c3a3b851f8187ea7f11fb41482f0241581e9a90f152323fc067a23c9a
9b21821b058164f8fbbd7c68fc4e2e5d175b5eb286dd7111c8a2b5be247f614c
Domains
staging-remoteprovisioning.sandbox.googleapis.com
accounts.google.com
www.google-analytics.com
apis.google.com
time.android.com
www.google.com
t.me
payments.google.com
google.com
play-lh.googleusercontent.com
www.googletagmanager.com
clients2.google.com
play.google.com
ssl.gstatic.com
fonts.gstatic.com
connectivitycheck.gstatic.com
www.gstatic.com
region1.google-analytics.com
content-autofill.googleapis.com
play.googleapis.com
URLs
http://connectivitycheck.gstatic.com/generate_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabnivb_n4bilsty9h4qsp8ymafocvzk8gxr4c=&request_id=5c55b0f2-46d7-4d12-80dd-990163fdadb7
https://t.me/tumonokasiperake
http://clients2.google.com/time/1/current?cup2key=9:6jvtbp92njq1umro_buoceo292t07i9qoho8rjf6clw&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://play.google.com/store/apps/details?id=com.lmr.lfm
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&laf=b64bin&json=standard
https://play.google.com/store/apps/details?id=com.lmr.lfm
https://fonts.gstatic.com/s/i/productlogos/avatar_anonymous/v4/web-32dp/logo_avatar_anonymous_color_1x_web_32dp.png
https://play-lh.googleusercontent.com/etayirtbvmjan2opqqnr0l76gczlbhfmegbl2nsjvchwiiyeoirk3a9ptfttpuzblea=w240-h480-rw
https://play-lh.googleusercontent.com/jyizb7tsazchgss7holbnkfmlbh-mln_11hdn8483vgxoebp7aqwnhnho4jtgj4yo53z7vvarewjbqmzzg=w48-h16-rw
https://play-lh.googleusercontent.com/jyizb7tsazchgss7holbnkfmlbh-mln_11hdn8483vgxoebp7aqwnhnho4jtgj4yo53z7vvarewjbqmzzg=s38-rw
https://play-lh.googleusercontent.com/22s8sy20xho69ircmeczqnfimghlbnlut_ia4a_vbpyzwl0feqs_22oispxqp9cy2sa=w526-h296-rw
https://play-lh.googleusercontent.com/qgze6_-elo3fn-mr1qddreoolm5tdqiq0iwaah6janrikrtykw4bnr-23ieqxybckrk=w526-h296-rw
https://play-lh.googleusercontent.com/zfmd0o-jtmmpmkdlkp5bcqubdvteek4pmgbbjnlpnyi5g5rumuyyypvqi82lozd-vw=w526-h296-rw
https://play-lh.googleusercontent.com/qkcna2kprwpndttvel6ctgbxlxflgdd0u6ridgg08gxshcmslyfam7alvjdkt7m0y2u=w526-h296-rw
https://play-lh.googleusercontent.com/ifstqoxdeluvv4t3kxkxp3otcufvwf5zqqjt7aixy4n2uavigccykxeg6ezv9fq10x1itpj1oorm=s20-rw
https://play-lh.googleusercontent.com/12usw7aflgz466ifdehktnmoaep_vhxdmkj6jebodzwcsefoc-thrx14mqe0r8kf9xczrpmqjts=s20-rw
https://play-lh.googleusercontent.com/w5dptvb8fhmkn5lbfzki_ohl3zi1rdc-aful19uk4f7np2nmjle5qqud6h0haeej977u3wh4yaq=s20-rw
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 2564
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 2932
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 4471
comments 0

DoubleTrouble: The Discord-Lurking Android Thief Emptying Wallets in Real-Time

Key Takeaways

  1. DoubleTrouble is a dual-stage, modular Android malware family focused on credential theft, fraud, and long-term persistence. The malware's abuse of Android Accessibility Services highlights a fundamental security challenge in mobile platforms.
  2. Its primary infection vector is smishing and malicious APK sideloading, often disguised as banking or delivery apps. The shift from phishing websites to Discord-hosted distribution shows threat actors continuously adapt to evade detection
  3. Businesses with BYOD environments face elevated risks, including account takeover and internal system compromise. Users in Europe and SE Asia, beware: Over 4,500 devices hit, targeting banks like ING and crypto apps.
  4. Detecting DoubleTrouble requires attention to accessibility permissions, network anomalies, and suspicious overlays. Prevention hinges on strong MDM policies, user education, and restricted sideloading.
  5. Evasion Evolution: obfuscated code and fake blocks dodge AV — layer defenses with behavioral monitoring.
  6. Dive into threat details fast with ANY.RUN’s Threat Intelligence Lookup — search "DoubleTrouble" or explore mobile banking trojans in their variety for IOCs, variants, and tailored defenses to stay ahead of campaigns.

Mobile banker samples found via TI Lookup Mobile banker sample analyses found via TI Lookup

  1. ANY.RUN's Interactive Sandbox with Android OS support helps detonate and analyze APK files to unpack behaviors safely and build custom detections. View analysis

DoubleTrouble sample in the Sandbox DoubleTrouble live sample detonated in ANY.RUN’s Sandbox

What is DoubleTrouble Malware?

DoubleTrouble is an evolving Android malware family built around modular components. It typically arrives disguised as a legitimate app, uses multiple layers of obfuscation, and deploys two coordinated modules (“double trouble”) that work together to:

  • Escalate privileges
  • Intercept device communications
  • Deploy specialized payloads based on attacker objectives

Its architecture allows operators to update capabilities in real time. Some variants behave like banking trojans; others serve as full-fledged spyware; more advanced strains use remote access tooling to turn a smartphone into a controllable endpoint.

What started as a phishing-driven menace impersonating European banks has morphed into a Discord-fueled nightmare, hosting malicious APKs that blend seamlessly into gaming and community chats. At its core, DoubleTrouble hijacks Android's Accessibility Services, granting it god-like control over the device without raising immediate alarms. This permission, often requested innocently for "app enhancements," lets the malware spy, steal, and sabotage in real-time.

Its sophisticated command-and-control architecture is what makes DoubleTrouble particularly dangerous. The malware can receive and execute dozens of commands from its C2 server, including simulating touch gestures, managing screen captures, injecting HTML overlays, blocking specific applications, and manipulating system settings. The malware also employs advanced anti-analysis techniques, uses dynamic overlays, and implements real-time visual capture to evade detection and maximize data exfiltration.

The malware is commonly distributed via rogue app stores, phishing campaigns, and malicious SMS messages. In 2025, several campaigns showed DoubleTrouble integrating MFA interception, credential theft, and automated transaction manipulation — expanding its role from pure data theft to active financial fraud.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

DoubleTrouble Trojan Victimology

DoubleTrouble primarily targets Android users throughout Europe, with campaigns specifically focusing on customers of major European banking institutions. The victimology extends beyond individual consumers to include:

  • Mobile banking users: Anyone using Android devices for financial transactions, particularly customers of European banks.
  • Enterprise employees: Corporate users accessing company banking systems or financial applications on Android devices.
  • Cryptocurrency holders: Users with cryptocurrency wallet applications on their mobile devices.
  • Small business owners: Individuals managing business finances through mobile banking applications.

The malware's shift to Discord-based distribution broadens its potential victim pool to include younger, tech-savvy users who frequent social media platforms and gaming communities.

How DoubleTrouble Malware Functions

The banker works through a multi-stage infection and operation process.

Initial Installation: The malware arrives disguised as a legitimate application, using the Google Play icon to establish trust. During installation, the actual malicious payload remains hidden within the app's Resources/raw directory, employing a session-based installation method to bypass permission restrictions.

Permission Acquisition: Upon first launch, the application prompts users to enable Android Accessibility Services: a powerful permission that grants extensive control over device functions. The request appears legitimate due to the convincing interface and trusted icon, leading many users to grant access without suspicion.

C2 Communication Establishment: Once activated, DoubleTrouble establishes communication with its command-and-control server. The malware receives instructions through a number of commands that enable remote operators to control infected devices.

Data Collection Infrastructure: The trojan implements multiple data collection mechanisms operating simultaneously:

  • A keylogger monitoring all text input
  • Screen recording capturing visual information
  • Application monitoring tracking which apps are launched and installed
  • Fake UI overlays harvesting credentials directly

Adaptive Evasion: DoubleTrouble employs sophisticated obfuscation techniques, using random two-word method names to hinder reverse engineering. The malware includes anti-analysis capabilities (start_anti and stop_anti commands) that scan UI elements for threats and can detect sandbox environments.

Exfiltration Process: Captured data is packaged into JSON payloads and transmitted to the C2 server. Screen captures are base64-encoded within these payloads, while keystroke logs and application lists are stored in XML files before exfiltration. This systematic approach ensures comprehensive data theft while maintaining stealth.

Persistent Operation: The malware maintains persistence through its accessibility service permissions, which are difficult for users to revoke once granted. It can block security applications that might detect and remove it, creating a self-protecting ecosystem that ensures continued operation.

Sandbox Analysis of a DoubleTrouble Banking Trojan Sample

ANY.RUN’s Interactive Sandbox provides isolated, instrumented environments where security researchers and analysts can safely execute suspicious files without risking production systems.

View a DoubleTrouble sample analysis

DoubleTrouble Sandbox analysis DoubleTrouble Android banker detonated in the Interactive Sandbox

In the analyzed sample, the initial reconnaissance and preparation phase is clearly visible, including telemetry collection and establishing persistence on the device. Let’s view the process tree revealed during the sandbox analysis:

DoubleTrouble process tree DoubleTrouble's processes

Immediately after launch, the application creates a service and moves it into what is known as foreground mode. This is a special type of background service in Android: the system treats it as “visible” to the user (it must display a persistent notification), so it assigns the service maximum priority and almost never terminates it, even under memory pressure. Power-saving restrictions also barely apply to such services. As a result, the malware achieves a very stable presence on the device.

At the same time, the application acquires a wake lock — a mechanism that prevents the phone from going into sleep mode. This allows the device to remain active for hours even when the screen is off.

Next, the telemetry collection begins. The malware extracts the phone number, the ISO code of the current network’s country, and the SIM card operator’s MCC and MNC. It then performs an HTTP GET request to the public ip-api service — a way to determine the victim’s geolocation based on their external IP.

The application checks whether the lock screen is currently displayed, monitors the user’s physical activity via sensors, tracks battery level and charging status, and subscribes to airplane mode change events. All of this helps the malware determine whether the device is actively in use at the moment and whether heavy operations can be executed without being noticed.

DoubleTrouble enumerates all installed applications, reads from and writes to SharedPreferences, and accesses protected system settings. It also dynamically registers a broadcast receiver and uses reflection. Calls to standard Android cryptographic APIs are visible as well.

The malware patiently establishes persistence, gathers context about the victim and the environment, bypasses system restrictions, and only then decides whether to activate its payload. Such cautious, multi-stage logic is typical of the new generation of mobile threats.

What DoubleTrouble can do to an endpoint device

Once installed, DoubleTrouble is capable of:

  • Keylogging and credential harvesting
  • Capturing SMS, messenger chats, notifications
  • Intercepting or bypassing 2FA/MFA codes
  • Screen recording and screenshot capture
  • Overlay attacks on banking/crypto apps
  • Remote access to device files and settings
  • Contact list scraping for further propagation
  • Voice call interception (in advanced variants)
  • Device lock manipulation for ransom scenarios
  • Silent installation of additional payloads
  • Some variants even disable antivirus apps and hide their own icon to avoid detection.

How DoubleTrouble threatens businesses and organizations

For organizations, DoubleTrouble poses risks far beyond individual device compromise:

  • Credential theft → account takeover → data breaches
  • Access to corporate email and messengers → internal compromise
  • Interception of MFA codes → bypassing zero-trust controls
  • Compromise of BYOD devices → lateral movement
  • Financial fraud via corporate banking apps
  • Leakage of sensitive internal documents
  • Corporate espionage via camera/microphone access

Mobile malware is increasingly becoming a preferred entry point for attackers because corporate mobile security is still underfunded and under-monitored compared to workstation security.

Gathering Threat Intelligence on DoubleTrouble Malware

Threat intelligence platforms enable teams to: -Track DoubleTrouble campaigns -Map IOCs to regions, industries, and TTPs -Block malicious IPs, hashes, and domains -Enrich SIEM/SOAR alerts with mobile-specific context

Sandbox analysis + threat intelligence gives defenders both behavioral and contextual visibility.

Use Threat Intelligence Lookup to check suspicious artifacts and view recent analysis sessions run by a community of 15,000 SOC teams.

SHA256:"657a08262d88b16624e99ddf95289537f264eb38e79de387643abc9b63ab124a".

File hash detecting DoubleTrouble via TI Lookup File hash detected as DoubleTrouble indicator via TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

DoubleTrouble is a fast-evolving Android threat that weaponizes accessibility abuse, overlay attacks, and modular payloads to steal credentials, bypass MFA, and enable financial fraud. For businesses relying on BYOD and remote work, it introduces significant risks — from account takeover to full corporate compromise.

To stay ahead, organizations need a combination of user education, MDM controls, mobile threat intelligence, and dynamic malware analysis. The earlier you identify malicious APKs in your environment, the faster you can break an attack chain and prevent financial or reputational damage.

Trial TI Lookup to start gathering actionable threat intelligence on mobile malware: just sign up to ANY.RUN.

HAVE A LOOK AT

DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
EvilTokens screenshot
EvilTokens
eviltokens
EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.
Read More
Remote Access Trojan screenshot
Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.
Read More
Phantom Stealer screenshot
Phantom Stealer
phantomstealer
Phantom Stealer is a commercially available Malware-as-a-Service infostealer targeting Windows systems. It harvests browser passwords, session cookies, payment data, cryptocurrency wallets, system information, screenshots, and application data.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More