Skip to content

Malware

Gustuff

Group-IB describes Gustuff as a mobile Android Trojan, which includes potential targets of customers in leading international banks, users of cryptocurrency services, popular ecommerce websites and ma

Gustuff is a Android malware family.

Background

Group-IB characterizes Gustuff as a mobile Android Trojan whose likely victims span customers of major international banks, cryptocurrency-service users, and shoppers on well-known ecommerce sites and marketplaces. Previously undocumented, Gustuff represents a new generation of malware built with fully automated routines aimed at draining both fiat and cryptocurrency from user accounts at scale. To do this it abuses the Accessibility Service, a feature meant to aid users with disabilities. Analysis of a Gustuff sample showed it carries web fakes capable of targeting Android app users of leading international banks such as Bank of America, Bank of Scotland, J.P.Morgan, Wells Fargo, Capital One, TD Bank, and PNC Bank, as well as crypto services including Bitcoin Wallet, BitPay, Cryptopay, and Coinbase. Group-IB researchers found that Gustuff could potentially hit users of over 100 banking apps, among them 27 in the US, 16 in Poland, 10 in Australia, 9 in Germany, and 8 in India, plus users of 32 cryptocurrency apps.


Source: Malpedia (Fraunhofer FKIE).