Cybersecurity researchers have identified a new Android banking trojan called Datzbro, which can perform device takeover (DTO) and perform fraudulent transactions, exploiting the elderly.

Dutch mobile security firm ThreatFabric discovered the campaign in August 2025, after users in Australia reported scammers running Facebook groupspromoting “senior travel.” Other regions targeted by the threat actors include Singapore, Malaysia, Canada, South Africa, and the United Kingdom.
The campaigns specifically target seniors looking for social activities, trips, meetups and similar events. These Facebook groups have been found to be sharing content generated by artificial intelligence (AI), claiming to organize various activities for seniors.
If potential targets express a desire to participate in these events, they are approached via Facebook Messenger or WhatsApp, where they are asked to download an APK file from a fake link (e.g. “download.seniorgroupapps[.]com”).
See also: New Spear-Phishing Attack Distributes DarkCloud Malware
“The fake websites urged visitors to install a so-called community app, claiming it would allow them to register for events, connect with members, and attend scheduled activities,” ThreatFabric said in a report.
Interestingly, the fake websites also contain placeholder links to download an iOS app, indicating that the attackers are seeking to target both mobile operating systemsby distributing TestFlight apps for iOS and tricking victims into downloading them.

If the victim clicks the button to download the Android app, it either directly deploys the malware to their device or deploys a dropper built using an APK binding service called Zombinder. This bypasses security restrictions in Android 13 and later.
Some of the Android apps that have been found to distribute Datzbro include:
– Senior Group (twzlibwr.rlrkvsdw.bcfwgozi) – Lively Years (orgLivelyYears.browses646 ) – ActiveSenior ( com.forest481.security) – DanceWave (inedpnok.kfxuvnie.mggfqzhl) – 黑豆帮 (io.mobile.Itool) – 麻豆传媒 (fsxhibqhbh.hlyzqkd.aois) – 麻豆传媒 (mobi.audio.aassistant) – 谷歌手机 (tvmhnrvsp.zltixkpp.mdok) – MT manager (varuhphk.vadneozj.tltldo) – MT manager (spvojpr.bkkhxobj.twfwf) – 大麦 (mnamrdrefa.edldylo.zish) – MT manager (io.red.studio.tracker)
Datzbro Android Trojan: Features
The malware, like other Android banking trojans, has a wide range of capabilities to record audio, take photos, access files and photos, and perform financial fraud through remote control, overlay attacks, and keystroke logging. It also relies on Android's accessibility services to perform remote actions on behalf of the victim.
See also: TamperedChef malware mimics productivity tools
A notable feature of Datzbro is the schematic remote control mode, which allows the malware to send information about all elements displayed on the screen, their location and content, allowing operators to recreate the layout and effectively take over the device.
The banking trojan can also act as a semi-transparent black overlay with custom text to hide malicious activity from the victim, as well as PIN lock screen and passwords related to Alipay and WeChat. In addition, it scans accessibility event logs for package names related to banks or cryptocurrency wallets and for text containing passwords, PINs, or other codes.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“Such a filter clearly shows the focus of the developers behind Datzbro, not only using its spying capabilities but also turning it into a financial threat,” ThreatFabric said. “With the help of keystroke logging, Datzbro can successfully capture login credentials for mobile banking apps entered by unsuspecting victims.”
See also: Cloud Security Alliance introduces new framework for SaaS
Datzbro is believed to be the work of a Chinese-speaking threat actor, given the presence of Chinese debug and logging strings in the malware’s source code. The malware was found to be connected to a command-and-control (C2) backend that is a Chinese-language desktop application, which sets it apart from other malware families that rely on web-based C2 panels.
ThreatFabric said that a compiled version of the C2 app has been leaked to a public virus share, suggesting that the malware may have leaked and is being freely distributed among cybercriminals.
