FluBot Returns: New Android Malware Targets Banking Credentials – Is Your Money Safe?
FluBot, a notorious Android banking trojan, is back with new techniques. Learn how it steals your financial data, how to protect yourself, and what to do if you’re infected.

The digital landscape is constantly evolving, and unfortunately, so are the threats. A particularly nasty piece of Android malware, known as FluBot, is making a comeback, and this time it’s demonstrating more sophisticated techniques to steal your financial information. While FluBot isn’t new – it was significantly disrupted in 2022 – threat actors have resurrected it with modifications designed to evade detection. This article dives deep into what FluBot is, how it operates, who is at risk, and, crucially, how to protect yourself and your hard-earned money.
What is FluBot and Why is it Dangerous?
FluBot (also known as Cabassos) is a sophisticated Android banking trojan. That means it’s malware specifically designed to steal your banking credentials and other sensitive financial data. It primarily spreads through SMS phishing, commonly known as “smishing.”
Here's what makes it particularly dangerous:
- Credential Theft: FluBot’s primary goal is to steal your usernames, passwords, and other login details for online banking apps and services.
- Data Exfiltration: Beyond login credentials, it can also steal SMS messages, contact lists, device information, and even your credit card details.
- Remote Access: The malware can grant attackers remote access to your device, allowing them to control it and potentially perform fraudulent transactions.
- Persistence: FluBot is designed to be persistent, meaning it can survive device reboots and attempts at removal.
- Evolving Tactics: The current resurgence demonstrates that the developers are continually updating the malware to avoid detection by security software.
How Does FluBot Infect Your Device? – The Smishing Attack
FluBot typically arrives on your device through deceptively crafted SMS messages. These messages often appear to be legitimate communications from trusted sources like:
- Banks: Messages claiming to be from your bank, alerting you to suspicious activity or requesting verification of recent transactions. They'll often include a link to "verify" your account.
- Delivery Services: Notifications about package deliveries, often from well-known companies like DHL, FedEx, or UPS. The link promises tracking information.
- Government Agencies: Messages falsely claiming to be from tax authorities or other government bodies, demanding urgent action or payment.
Image Suggestion: A screenshot of a typical FluBot smishing SMS message, blurred to protect sensitive information, with the alt text "Example of FluBot Smishing SMS Message targeting banking users."
The key is the link within the message. Clicking this link doesn't take you to a legitimate website. Instead, it redirects you to a fake website designed to mimic the real one. This is where FluBot comes into play.
Here’s the typical infection flow:
- Receive a Smishing SMS: You receive a text message with a malicious link.
- Click the Link: You click the link, believing it’s legitimate.
- Fake Website: You’re directed to a fake website that looks like a genuine login page (e.g., your bank's website).
- Download Malware: The website prompts you to download an app, often disguised as a legitimate update or a seemingly harmless utility. This app is actually the FluBot malware. Android may warn you about downloading from an unknown source; ignoring this warning is a critical mistake.
- Installation and Execution: You install and open the downloaded app, giving it the permissions it needs to operate. This is where FluBot begins stealing your data.
Who is at Risk?
While anyone with an Android device is potentially vulnerable, certain groups are at higher risk:
- Users who readily click on links in SMS messages: The easiest way to get infected is to simply click the malicious link.
- Users who ignore Android’s security warnings: Android will often warn you before installing apps from unknown sources. Ignoring these warnings significantly increases your risk.
- Users with older Android versions: Older versions of Android may have security vulnerabilities that FluBot can exploit.
- Users without robust mobile security solutions: Having a reputable mobile security app installed can provide an extra layer of protection.
- Users who use weak or reused passwords: Even if FluBot steals your credentials, strong, unique passwords can limit the damage.
How to Protect Yourself from FluBot
Prevention is always better than cure. Here’s how to protect yourself from FluBot:
- Be Skeptical of SMS Messages: Never click on links in SMS messages, especially if they ask you to verify your account details or offer something too good to be true.
- Verify Directly: If you receive a suspicious message claiming to be from your bank or another organization, contact them directly through their official website or phone number (found independently – not from the SMS).
- Enable Google Play Protect: Google Play Protect is built into Android and helps scan apps for malware. Make sure it's enabled in your Google Play Store settings.
- Keep Your Android Device Updated: Install the latest Android updates as soon as they become available. These updates often include crucial security patches.
- Install a Reputable Mobile Security App: A good mobile security app like can provide real-time protection against malware, phishing attacks, and other threats. Consider other options such as Bitdefender, McAfee, and Kaspersky.
- Use Strong, Unique Passwords: Use strong, unique passwords for all of your online accounts, especially your banking and financial accounts. Consider using a password manager to generate and store your passwords securely.
- Enable Two-Factor Authentication (2FA): Whenever possible, enable 2FA on your accounts. This adds an extra layer of security by requiring a second form of verification (e.g., a code sent to your phone) in addition to your password.
- Review App Permissions: Regularly review the permissions granted to apps on your device. If an app requests permissions that seem unnecessary, revoke them.
What to Do if You Think You're Infected
If you suspect your Android device has been infected with FluBot:
- Disconnect from the Internet: Immediately disconnect your device from Wi-Fi and mobile data to prevent further data leakage.
- Run a Malware Scan: Use a reputable mobile security app to perform a full system scan.
- Change Your Passwords: Change the passwords for all of your important accounts, especially your banking and financial accounts. Do this from a clean device.
- Contact Your Bank: Inform your bank immediately about the potential compromise. They can monitor your accounts for fraudulent activity and take appropriate action.
- Factory Reset (Last Resort): If you’re unable to remove the malware with a security app, a factory reset may be necessary. This will erase all data on your device, so back up your important files first (if possible and safe).
- Report to Authorities: Report the incident to your local cybersecurity authority.
Image Suggestion: An image of a smartphone with a security app running a scan, with the alt text "Running a malware scan on an Android device to detect and remove FluBot."
Staying Vigilant in a Changing Threat Landscape
FluBot’s resurgence is a stark reminder that the threat of mobile malware is very real. The tactics used by cybercriminals are constantly evolving, so it’s essential to stay informed and proactive about your mobile security. Regularly updating your knowledge of the latest threats and following the security best practices outlined above can significantly reduce your risk of falling victim to FluBot and other malicious attacks.
Table Summarizing FluBot Key Information
| Feature | Description |
|-------------------|-------------------------------------------------| | Type | Android Banking Trojan | | Spread Method | SMS Phishing (Smishing) | | Target | Banking credentials, financial data, SMS messages | | Main Function | Steal financial information, remote access | | Prevention | Skepticism, updates, security apps, strong passwords| | Removal | Malware scan, password reset, factory reset |
Disclaimer: This article contains affiliate links. If you click on one of these links and make a purchase, we may receive a commission. This does not affect the price you pay. We only recommend products and services that we believe are helpful and beneficial. https://example.com/ is a link to products available on Amazon. is a link to Norton's mobile security product.