Netskope Threat Labs

Alien

ATP Sandbox Adv. Heuristics

Alien is an Android banking trojan that steals credentials from financial applications and uses overlay attacks to trick victims into entering their login details on fake screens placed over legitimate apps. It can intercept SMS messages to defeat text based two factor authentication, and it borrows code from other Android families such as Anubis, which makes it easy for criminals to maintain. Researchers have observed it targeting customers of banks across Europe and other regions.

First seen
March 2022
Last seen
October 2026
Alert Name
Archive-ZIP.Trojan.Alien
ByteCode-JAVA.Trojan.Alien
ByteCode-MSIL.Trojan.Alien
ByteCode-SWF.Trojan.Alien
Document-Excel.Trojan.Alien
Document-Office.Trojan.Alien
Document-OLE.Trojan.Alien
Document-PDF.Trojan.Alien
Document-RTF.Trojan.Alien
Document-Word.Trojan.Alien