Octo2 banking trojan is taking over Android phones and stealing cash — how to stay safe

A picture depicting how banking trojans steal credit card data
(Image credit: Shutterstock)

After a two-year hiatus, the Octo malware has returned with improved capabilities that make it easier for hackers to use it to completely take over the best Android phones.

As reported by The Hacker News, security researchers at ThreatFabric have discovered a new version of this Android banking trojan called Octo2. So far, it’s mainly been used in campaigns across Europe but this malware could easily be reconfigured to target Android users in the U.S., Canada and other countries around the world.

What makes Octo2 so dangerous is the fact that it’s currently being distributed in malicious versions of popular apps including Google Chrome and NordVPN. Once your phone is infected with this malware, not only can hackers completely take it over but they can also perform fraudulent transactions right from the device itself. This helps the hackers behind this campaign avoid being detected by banks and other financial institutions.

Here’s everything you need to know about this new version of Octo 2 including how it has managed to infiltrate legitimate apps along with some tips on how to stay safe from Android malware.

Hiding in legitimate apps

One phone with skull and crossbones on screen among several other clean-looking phones.

(Image credit: Marcos_Silva/Shutterstock)

The original Octo malware was first discovered back in 2022. However, it’s actually based on the Exobot malware that was first detected in 2016 according to a blog post from ThreatFabric.

The reason we’re now seeing the emergence of Octo 2 is due to the fact that the source code for the original version leaked earlier this year. With Octo’s source code in hand, hackers have begun creating their own variations of this malware to use in their attacks.

At the same time, Octo has moved to a malware-as-a-service (MaaS) operating model in which other cybercriminals pay its developer a small fee to use the malware in their own attacks. Octo’s developer even promoted this new version by informing its clients that existing users would be able to get Octo2 for the same price with early access.

To make their attacks harder to detect, the hackers deploying Octo2 are using it alongside an APK binding service called Zombinder. This may sound a bit too technical but here’s the gist, Zombinder lets hackers take legitimate Android apps and add malware to them in such a way that to the end user, they appear nearly identical to the original app.

Octo2 is downloaded by these rogue Android apps by convincing users that they need to install a “necessary plugin”. If an unsuspecting user falls for this, hackers then have complete control over their phone remotely which enables them to carry out all manner of attacks.

How to stay safe from Android malware

A hand holding a phone securely logging in

(Image credit: Google)

When it comes to staying safe from Android malware, the first and most important thing is that you avoid installing apps from unknown sources. This means only installing apps from trusted app stores like the Google Play Store, Samsung Galaxy Store or the Amazon Appstore.

Sideloading apps may be convenient but by doing so, you put yourself at risk of installing a malicious app that can then infect your phone with malware. This is why you should avoid doing so unless, of course, you need to install an app for work that can’t be hosted on an official store. However, this is extremely rare and most employers would never ask you to do this.

From here, you want to ensure that Google Play Protect is enabled on your Android phone. This free app comes pre-installed on most Android devices and it can scan all of your existing apps and any new ones you install for malware. For extra protection though, you should also consider using one of the best Android antivirus apps alongside it.

Now that Octo’s source code is out in the open, it’s very likely we will see even more variations of the malware. However, if you’re careful online, avoid sideloading apps and keep your phone updated with Google Play Protect enabled, you should be fine.

More from Tom's Guide

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
One phone with skull and crossbones on screen among several other clean-looking phones.
Malicious iPhone apps are spreading screenshot-reading malware on the Apple App Store — how to stay safe
Green skull on smartphone screen.
Hackers are using the Amazon Appstore to spread malware — delete this malicious app now
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Latest in Malware & Adware
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
Latest in News
Gemini logo on smartphone
Google is giving away Gemini's best paid features for free — here's the tools you can try now
Samsung Galaxy S23 Ultra
Older Samsung phones are finally getting One UI 7 — here's all the devices
A photo of Apple CarPly in use
Apple CarPlay just got a welcome upgrade in iOS 18.4 — what you need to know
Billy Bob Thornton in Landman
‘Landman’ season 2 is official after Paramount Plus renews Taylor Sheridan drama
Everybody Live With John Mulaney
Netflix top 10 shows — here's the 3 worth watching right now
the Orbea Denna on a gravel track
Orbea's new e-bike is designed to tackle both road and gravel — and you can build your own