OverlayPhantom: The Android Banking Trojan Using Your Own Phone’s Accessibility Service Against You

OverlayPhantom: The Android Banking Trojan Using Your Own Phone’s Accessibility Service Against You

A new Android banking trojan has been identified targeting more than 180 financial applications across ten countries, and it is doing so using a technique that makes it extraordinarily difficult for users to detect: it renders a convincing fake interface directly over the real banking application you are trying to use.

Researchers have named this malware OverlayPhantom. Published this week, the technical analysis reveals a threat that combines phishing overlays, real-time screen streaming, and abuse of Android’s Accessibility Services framework into a single, coordinated credential theft operation one that is particularly relevant to users of UPI-linked banking applications in India.

How OverlayPhantom Operates

When a victim opens a targeted banking application, OverlayPhantom detects the launch event and immediately renders a pixel perfect fake interface over the top of the genuine app. The user sees what appears to be their bank’s legitimate login screen. They enter their credentials. Those credentials are captured and exfiltrated to attacker controlled servers in real time.

Simultaneously, OverlayPhantom activates screen streaming, giving the attacker a live view of everything happening on the device. Combined with the captured credentials, this provides attackers with the information needed to initiate fraudulent transactions either manually or through automation before the victim realises anything unusual has occurred.

The Accessibility Services abuse is particularly insidious. Android’s Accessibility framework is designed to assist users with disabilities it allows apps to read screen content and interact with the interface on the user’s behalf. OverlayPhantom exploits this legitimate system framework to monitor which applications are opened, trigger the overlay at the correct moment, and capture data entered by the user without requiring any additional permissions beyond those granted during installation.

The India Angle

With India being among the ten countries confirmed as targeted, and the trojan explicitly designed to target financial applications including UPI-linked banking apps, the implications for Indian consumers and enterprises are direct.

India processed over 130 billion UPI transactions in the financial year 2025-26. The scale of the UPI ecosystem and the trust that users place in their banking applications makes the population of potential OverlayPhantom victims enormous. The trojan’s ability to target apps rather than specific banks means that any financial application on an infected device is a potential target, regardless of which institution it belongs to.

For enterprise security teams, the threat extends beyond personal banking. Employees who use UPI or mobile banking applications on devices that also access corporate email, VPN, or cloud storage represent a point of intersection between personal financial risk and enterprise security exposure.

The Accessibility Permission Problem

The core challenge OverlayPhantom exposes is that Android users are routinely asked to grant Accessibility permissions by legitimate applications screen readers, automation tools, and certain enterprise security products making it difficult to identify malicious requests. Once Accessibility permission is granted, the range of capabilities available to the malicious application is extensive.

Security teams and mobile device management platforms should review which applications on employee devices hold Accessibility permissions and evaluate whether each grant is justified.

What Users Should Do

  • Download financial applications only from official app stores (Google Play), and verify the developer name before installation
  • Review applications holding Accessibility permissions on your device and revoke any that cannot be identified as legitimate
  • Enable Google Play Protect and keep it active on all Android devices
  • Be alert to any financial application that behaves differently than expected slower loading, unusual prompts, or requests to re-enter credentials unexpectedly
  • Report suspicious app behaviour to your bank and to CERT-In through the national cybercrime reporting portal

Leave a Reply

Your email address will not be published.