BianLian is a Android banking trojan first seen in October 2018 as a dropper for Android malware, such as Anubis. It evolved to bypassing security protocols within the official Google Play store. This trojan receives periodic updates to increase functionality and evade protections. BianLian requests permissions that allow it to read, send, and receive text messages; monitor and make calls; insert overlays on banking applications; lock the device screen; and, most recently, it added a screencast module. This module allows the trojan to record the screen of the device, which can be used to steal information such as usernames, passwords, and other sensitive information. As of July 2019, the trojan appears to still be under active development.

Technical Details and Reporting

  • Fortinet provides a list of indicators and technical analysis, here.