The Curated Daily
← Back to the archiveFluBot · 6 min read
FluBot

FluBot: The New Android Malware Targeting Your Financial Data

Learn about FluBot, a dangerous new Android malware spreading through SMS phishing. Discover how it steals banking credentials & protect your financial information.

By the editors·Thursday, July 2, 2026·6 min read
Crop concentrated man in warm clothes entering credentials of credit card on mobile phone while standing in street in daytime
Photograph by Anete Lusina · Pexels

A new and increasingly sophisticated Android malware called FluBot is making headlines, and it’s posing a significant threat to your financial security. Unlike some malware that broadly seeks to disrupt devices, FluBot is specifically designed to steal your banking credentials and other sensitive financial data. This article will delve into what FluBot is, how it spreads, what it does, and, most importantly, how you can protect yourself.

What is FluBot?

FluBot (also known as Cabassos) is a type of Android banking trojan that spreads primarily through smishing – SMS phishing. It’s not a brand new threat; it’s been around since late 2021, initially targeting users in Europe. However, recent campaigns have significantly broadened its reach, now impacting users in the US, Canada, and beyond. What makes FluBot particularly dangerous is its ability to bypass Android’s security measures and its constantly evolving tactics.

FluBot isn’t downloaded directly by users knowingly. It arrives deceptively, disguised as legitimate text messages. This is the core of the smishing attack.

**(Image suggestion: A screenshot of a typical smishing SMS message – “Your package couldn’t be delivered, update here…” –

How Does FluBot Spread? (The Smishing Technique)

The primary method of spreading FluBot is through deceptively crafted SMS messages. These messages typically lure users into clicking a malicious link. Common themes used in these smishing attacks include:

  • Fake Delivery Notifications: Messages claiming an issue with a package delivery from a well-known courier (e.g., FedEx, DHL, UPS).
  • Bank Alerts: Messages impersonating your bank, warning of suspicious activity on your account or requiring you to verify your details.
  • Fake Voicemails: Messages suggesting you have a missed voicemail and providing a link to listen to it.
  • Subscription Notifications: Messages about expiring subscriptions or payment failures.

The links in these messages lead to websites that look legitimate, often mimicking the appearance of popular services. However, these websites are designed to download the FluBot malware onto your Android device. Once installed, the malware begins its malicious activities.

It's important to note that the messages are often highly personalized, making them even more convincing. Attackers use data breaches and publicly available information to craft messages that feel targeted and urgent.

What Does FluBot Do Once Installed?

Once FluBot gains access to your device, it's capable of a range of harmful activities, all centered around stealing your financial information:

  • Data Harvesting: It steals sensitive data such as banking login credentials, credit card details, contact lists, SMS messages, and other personal information.
  • Banking Credential Theft: FluBot actively searches for banking apps on your device. When it finds them, it presents a fake login screen designed to mimic the legitimate app. Any credentials you enter on this fake screen are immediately sent to the attackers.
  • SMS Interception: It can intercept your SMS messages, including two-factor authentication (2FA) codes, further compromising your accounts. This is a particularly dangerous feature as it bypasses a key security measure.
  • Device Control: FluBot can also gain control over certain device functionalities, allowing it to perform actions without your knowledge.
  • Spreading the Infection: Perhaps most alarming, FluBot sends the same smishing SMS messages to your contacts, effectively turning your phone into a tool for spreading the malware to others. This is how it rapidly proliferates.
  • Information Exfiltration: Continually searches for and transmits collected data to a command-and-control server controlled by the attackers.

How to Protect Yourself from FluBot

Protecting yourself from FluBot requires a multi-layered approach. Here’s a breakdown of essential security measures:

  • Be Suspicious of All Links in SMS Messages: Never click on links in text messages from unknown senders. Even if the message appears to be from a trusted source, be cautious. If you're unsure, contact the company directly through official channels (e.g., their website or customer service number).
  • Enable Google Play Protect: Google Play Protect is built-in malware protection for Android devices. Make sure it’s enabled and up-to-date. It scans apps before and after installation.
  • Keep Your Android Device Updated: Software updates often include security patches that address vulnerabilities exploited by malware. Enable automatic updates or regularly check for updates yourself.
  • Install a Reputable Mobile Security App: Consider installing a third-party mobile security app, such as or similar, for an extra layer of protection. These apps offer real-time malware scanning, anti-phishing features, and other security benefits.
  • Be Wary of Permissions Requested by Apps: Pay attention to the permissions requested by apps you install. If an app asks for permissions that don't seem relevant to its function, be suspicious.
  • Enable Two-Factor Authentication (2FA): While FluBot can intercept SMS-based 2FA codes, it's still a valuable security measure. Where possible, use authenticator apps (like Google Authenticator or Authy) instead of SMS for 2FA.
  • Backup Your Data Regularly: In the unfortunate event that your device is infected, having a recent backup can help you restore your data without losing important information.
  • Be Careful with Public Wi-Fi: Avoid conducting sensitive transactions (like online banking) on public Wi-Fi networks. Use a Virtual Private Network (VPN) to encrypt your internet connection.

**(Image suggestion: A smartphone displaying a mobile security app scanning for threats –

What to Do If You Think You've Been Infected

If you suspect your Android device has been infected with FluBot:

  • Disconnect from the Internet: Immediately disconnect your device from Wi-Fi and mobile data to prevent further communication with the attackers.
  • Perform a Malware Scan: Use your mobile security app or Google Play Protect to scan your device for malware.
  • Factory Reset (Last Resort): If a scan doesn’t remove the malware, a factory reset may be necessary. However, this will erase all data on your device, so ensure you have a recent backup.
  • Change Your Passwords: Change your passwords for all important accounts, including banking, email, and social media.
  • Monitor Your Financial Accounts: Keep a close eye on your bank accounts and credit card statements for any unauthorized activity.
  • Inform Your Bank: Notify your bank immediately if you suspect your financial information has been compromised.

FluBot’s Evolution and Future Threats

FluBot is a constantly evolving threat. The attackers are continually refining their tactics to bypass security measures and improve their success rate. Recent developments include:

  • New Smishing Techniques: The attackers are using increasingly sophisticated smishing messages that are harder to detect.
  • Targeting New Regions: FluBot is expanding its reach to new countries and regions.
  • Bypassing Android Security Features: The malware is becoming more adept at bypassing Android's built-in security features.

This means that staying informed about the latest threats and best practices is crucial for protecting yourself. Cybersecurity is an ongoing process, not a one-time fix.

**(Image suggestion: A graphic illustrating the evolution of malware threats over time –

Staying Vigilant: Resources and Tools

Here are some helpful resources to stay informed about FluBot and other Android malware threats:

Investing in mobile security, practicing safe browsing habits, and remaining vigilant about suspicious messages are the best defenses against FluBot and other emerging Android threats. Consider a robust antivirus solution like those available from https://example.com/ for comprehensive protection.

Disclaimer:

This article contains affiliate links. If you purchase a product or service through these links, we may receive a small commission at no extra cost to you. This helps support our website and allows us to continue providing valuable content. We only recommend products and services that we believe are helpful and relevant to our audience.

Pass it onX·LinkedIn·Reddit·Email
Filed under:FluBot·Android malware·financial malware·mobile banking security·SMS phishing·smishing
The Sunday note

If this was your kind of read.

Sign up for the morning email — short, hand-written, and sent only when there's something worth your time.

Free, sent from a person, not a system. Unsubscribe in one click whenever.

Keep reading

The archive →