Malware
Catelites
Catelites Bot (identified by Avast and SfyLabs in December 2017) is an Android trojan, with ties to CronBot.
Catelites is a Android malware family.
Background
Catelites Bot, spotted by Avast and SfyLabs in December 2017, is an Android trojan linked to CronBot. After the malicious app is installed, the operators rely on social engineering and window overlays to coax credit card information out of the victim. Distribution appears to occur through counterfeit apps on third-party stores (outside Google Play) or via malvertising. Once installed and activated, the app places bogus Gmail, Google Play, and Chrome icons on the device. It also pushes a fake system notification claiming the user must re-authenticate with Google Services, prompting them to enter their credit card details. At present the malware ships overlays for more than 2,200 banking and financial-institution apps.
Source: Malpedia (Fraunhofer FKIE).