Skip to content
July 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • The author of Exobot Bank Trojans sell the source code
  • Malware

The author of Exobot Bank Trojans sell the source code

Do Son January 20, 2018 4 minutes read
Add Daily CyberSecurity as a preferred source on Google

According to bleepingcomputer media on January 17, the security researcher said the source code of an advanced Android Exobot bank Trojan sold to different people in the well-known hacker forum, the situation of Android users will get worse.

This worrisome Trojan is an Android malware that first appeared in a June 2016 malware attack scenario. Like most professionally encoded desktops or mobile banking Trojans today, Exobot has been rented to customers on a monthly basis.

Although customers do not have access to the Exobot Trojan source code, they can use the Exobot author’s configuration panel to compile malicious applications for each client-defined setting. Then, the renter must distribute these applications to the victims. Exobot has been one of the most active Android mobile Trojans for the past two years (including BankBot, GM Bot, Mazar Bot, and Red Alert).

Initially, some security companies called the Trojan Marcher but eventually called it by its author’s name. In the second half of 2016, Exobot’s initial profits spurred the authors of Exobot to create Exobot v2. Bleeping Computer covers the rise of Exobot v2 as Trojans make dark webs, hacker forums, XMPP spam, and even publicize the public Internet.

According to press past evidence of dialogue with many security researchers, Exobot appears to be a lucrative business that is being used by users in many countries around the world.

Exobot authors sell bank Trojans

Unexpectedly, the author of Exobot made a big move with the generic “Android” alias, though in hindsight this may pose a lot of problems for prospective users. Just recently, the author of Exobot decided to close the Exobot rental program and sell the source code to a handful of customers.

Below are two pictures of Exobot’s author sales ad, provided by Cengiz Han Sahin, a mobile security researcher at SfyLabs.

Sahin, a security official, states that this statement in the field of malware generally means one of two things:

Either malicious actors noticed a surge in interest from law enforcement or their competitors fighting back to market share, either because his business is indeed very rich and risks or income are no longer motivated by profit.

Public concern Exobot source code is public

However, despite these reasons, there is no doubt that the sale of Exobot will have a profound impact on the Android malware attack scenario, if not immediately.

A reporter has reported many such incidents in the past. According to the reporter’s experience and Sahin’s prediction, it is only a matter of time before the source code is leaked online. Such sales are almost never kept secret, and when the author of Exobot does not provide the buyer’s required support, the dissatisfied customer divulges the source code. For example, in the past decade, many home desktop banking Trojans have been leaked.

Once leaked, the Exobot code will resemble the fate of Slempo, BankBot, and GM Bot Android Trojans, reorganizing into hundreds of branching Trojans, reducing the cost and technical skills needed to move to mobile malware scenarios.

Exobot sells or derives new malware activities

However, new users of the Trojan are ready to use before the low-skill malicious actors leak the Exobot version.

Sahin, a security official, said: “Less than a month after the malicious actors began selling the Exobot source code, new activities were discovered in Austria, the United Kingdom, the Netherlands and Turkey, Turkey, the country most affected by these activities, for more than 4,400 Taiwan equipment involved.

The increase in this malicious Exobot application is due to some private sales of Exobot source code. If the source code leaks, the scale of Exobot attacks may exceed the safety of people’s imagination, as the same as the BankBot Trojan. It is reported that BankBot leaked online at the end of 2016. It has always been the heart of malicious applications spread through the Google Play Store,

Decentralized Android operating systems, mobile operators that do not deliver patches in time, and Google’s game store team do not seem to be able to keep up with the malware authors for a number of reasons that make Android users a serious disadvantage in moving malware. The only way to protect most users is to move anti-virus solutions and some common sense, such as refusing to install applications from untrusted sources, not installing game store applications that require unnecessary permissions, and more.

Source: BleepingComputer

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • Beyond the URL: How “Cookie-Gated” Web Shells Hide Silent RCE in Plain Sight
  • JPCERT Exposes ‘MalDoc in PDF’: The Stealthy Cyber Threat
  • Compromised Routers: Tool of Choice for Crime & Espionage
  • Mirai variant botnet targets the financial sector
  • Lampion Malware Returns with ClickFix Tactics to Target Portuguese Sectors
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Exobot Bank Trojans

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-58644CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2023-4346CVSS 7.5
    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to...
    CISA KEV📅 Added to KEV: Jul 15, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-13439CVSS 9.8
    The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to...
  • CVE-2026-64625CVSS 9.8
    AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps...
  • CVE-2026-53595CVSS 9.4
    FreeScout is a free help desk and shared inbox built with PHP's...
  • CVE-2026-44231CVSS 9.1
    RT is an open source, enterprise-grade issue and ticket tracking system. Versions...
  • CVE-2026-63766CVSS 9.8
    GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where...
  • CVE-2026-63767CVSS 9.8
    ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization...
  • CVE-2026-39878CVSS 9.3
    Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability...
  • CVE-2026-54051CVSS 9.9
    Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent...
  • CVE-2026-41252CVSS 9.8
    xrdp is an open source RDP server. Versions 0.10.6 and prior contain...
  • CVE-2026-35048CVSS 9.8
    The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.