• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    UNC6783, BPO, Google Threat Intelligence Group, Okta, Help Desk, Phishing

    UNC6783 Turns BPO Providers into Cyberattack Gateways

    SOHO router

    Russian Hackers Exploit SOHO Routers for DNS Hijacking Campaign

    Signature Healthcare cyberattack

    Signature Healthcare Cyberattack Causes Service Disruptions, Treatment Delays

    Bitcoin Depot cyberattack

    Bitcoin Depot Discloses $3.6 Million Crypto Theft Following System Breach

    ClickFix-style macOS attack

    ClickFix macOS Attack Uses Script Editor to Bypass Security Controls

    Eurail data breach

    Eurail Confirms Security Breach Affecting Over 300,000 U.S. Individuals

    Flowise RCE vulnerability

    Critical Flowise RCE Vulnerability Actively Exploited, Thousands of Systems at Risk

    Winona County cyberattack

    Gov. Tim Walz Deploys National Guard After Winona Cyberattack Disrupts Services

    APT28

    FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    phishing emails cyberattacks

    75% of Cyberattacks Start with Phishing Emails, UAE Cyber Council Says

    AVrecon, AVrecon Malware, Home Router, FBI, SocksEscort, Proxy Network

    FBI Warns of AVrecon Malware Targeting Network Devices Across 163 Countries

    Axios npm Supply Chain Attack, Supply Chain Attack, Axios, npm Package, GTIG, CTI, North Korea, Lazarus Group, Lazarus

    North Korea’s Lazarus Group Behind the Axios npm Supply Chain Attack

    CERT-UA, AGEWHEEZE, RAT, Remote Access Trojan, Government, Hospitals

    Hackers Impersonate Ukrainian CERT to Plant a RAT on Government, Hospital Networks

    Russian information operation

    Latvia Warns of Disinformation Campaign Targeting Baltic States

    Black Friday discounts

    30% of Retailers Fail to Show Accurate Discounts, EU Probe Reveals

    DSA child protection investigation

    Snapchat Faces EU Child Safety Probe Under Digital Services Act

    Foreign-Made Router, FCC Ban, FCC

    The FCC Just Blocked Every New Foreign-Made Router from the U.S. Market

    Iran Telegram malware

    Iran-Linked Hackers Use Messaging Platform to Target Dissidents and Journalists

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    UNC6783, BPO, Google Threat Intelligence Group, Okta, Help Desk, Phishing

    UNC6783 Turns BPO Providers into Cyberattack Gateways

    SOHO router

    Russian Hackers Exploit SOHO Routers for DNS Hijacking Campaign

    Signature Healthcare cyberattack

    Signature Healthcare Cyberattack Causes Service Disruptions, Treatment Delays

    Bitcoin Depot cyberattack

    Bitcoin Depot Discloses $3.6 Million Crypto Theft Following System Breach

    ClickFix-style macOS attack

    ClickFix macOS Attack Uses Script Editor to Bypass Security Controls

    Eurail data breach

    Eurail Confirms Security Breach Affecting Over 300,000 U.S. Individuals

    Flowise RCE vulnerability

    Critical Flowise RCE Vulnerability Actively Exploited, Thousands of Systems at Risk

    Winona County cyberattack

    Gov. Tim Walz Deploys National Guard After Winona Cyberattack Disrupts Services

    APT28

    FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    phishing emails cyberattacks

    75% of Cyberattacks Start with Phishing Emails, UAE Cyber Council Says

    AVrecon, AVrecon Malware, Home Router, FBI, SocksEscort, Proxy Network

    FBI Warns of AVrecon Malware Targeting Network Devices Across 163 Countries

    Axios npm Supply Chain Attack, Supply Chain Attack, Axios, npm Package, GTIG, CTI, North Korea, Lazarus Group, Lazarus

    North Korea’s Lazarus Group Behind the Axios npm Supply Chain Attack

    CERT-UA, AGEWHEEZE, RAT, Remote Access Trojan, Government, Hospitals

    Hackers Impersonate Ukrainian CERT to Plant a RAT on Government, Hospital Networks

    Russian information operation

    Latvia Warns of Disinformation Campaign Targeting Baltic States

    Black Friday discounts

    30% of Retailers Fail to Show Accurate Discounts, EU Probe Reveals

    DSA child protection investigation

    Snapchat Faces EU Child Safety Probe Under Digital Services Act

    Foreign-Made Router, FCC Ban, FCC

    The FCC Just Blocked Every New Foreign-Made Router from the U.S. Market

    Iran Telegram malware

    Iran-Linked Hackers Use Messaging Platform to Target Dissidents and Journalists

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Roamer Banking Trojan Advertised on Phishing Websites

CRIL researchers discovered that the scammers behind the banking trojan utilize their own websites, apps, and a Telegram channel to target unsuspecting individuals.

Editorial by Editorial
June 15, 2023
in Firewall Daily, Malware News
0
Roamer Banking Trojan
661
SHARES
3.7k
VIEWS
Share on LinkedInShare on Twitter

A newfound banking trojan named ‘Roamer’ has been found exploiting users on fraudulent cloud mining platforms.

The scammers behind the Roamer banking trojan engage with users through carefully crafted phishing websites. These fraudulent websites prompt users to download applications that are specifically designed to pilfer sensitive data.

Meanwhile, the scammers exploit this opportunity to monitor and extract information related to cryptocurrency transactions.

What the Roamer banking trojan steals

The Roamer banking trojan can take commands to execute malicious tasks.

The Cyble Research & Intelligence Labs (CRIL) discovered instances where the Roamer Banking Trojan was capable of executing a range of operations upon receiving the command “x0000myview”. These included codes such as pinUnlock, slideup, multiClick and more to carry out a multitude of tasks.

The Roamer banking trojan accesses the camera of the targeted user, files in the device, location of the user, SMSes, and takes screenshots of the data on the screen.

report-ad-banner

How the Roamer banking trojan targets people

Roamer banking trojan
Screenshot of the phishing website with the Roamer banking trojan (Photo: Cyble blog)

CRIL researchers noted that the scammers behind the `banking trojan use their own websites, apps, and a Telegram channel to lure unsuspecting individuals. Roamer banking trojan is designed to work on Android devices.

“In recent years, cloud mining has become a convenient option for individuals interested in entering the cryptocurrency realm without extensive technical expertise or costly mining hardware,” the Cyble blog stated. Cloud mining allows users to remotely mine cryptocurrencies including Bitcoin and Ethereum.

The phishing sites that users were caught in the cybercrime were –

  • Hxxps://cloudmining.uk[.]com
  • Hxxps://cloud-miner[.]cc
  • Hxxps://cloud-miner[.]top – This website differed in appearance from the above two as shown below:
Roamer banking trojan
Screenshot of the fraudulent websites used by scammers (Photo: Cyble blog)

The Telegram channel called Cloud Mining was detected by CRIL researchers. This channel was operative since May 15, 2023, suggesting the scam is fairly new and may not have had many victims so far.

Roamer banking trojan
Screenshot of the Telegram channel used to post about the Roamer malware (Photo: Cyble blog)

The Telegram channel, which has over five thousand subscribers at the time of writing, was used to post regular updates about cloud mining schemes.

The channel description reads, “Cloud mining allows you to use the computing power of mining equipment hosted in specialized data centers without owning or maintaining the equipment.”

Roamer banking trojan
Screenshot of a Telegram post with the malicious link (Photo: Cyble blog)

A post found by Cyble on Cloud Mining called on users to download a fraudulent link claiming to be legitimate and also offered a commission for inviting other users. An APK file named CloudMining.apk is asked to be downloaded.

Creating an account on the Roamer-infected Cloud Mining website

Users are asked to register on the scam website of Cloud Mining and enter their details for the same. They are asked to recharge their accounts by transferring TRX currency. The website has a QR code to start the transactions.

The Roamer mining malware seeks permission to enable accessibility service which it uses to access the data on the device.

Researchers also found 15 other samples of malware that duped users with names similar to games and shopping malls.

The Roamer crypto malware targets 17 wallets including Coinbase, Bitso, and Huobi. It also accesses data from 9 banking applications on the device namely HDFC, MSB, and SCB mobile banking.

Users are urged not to click on random websites related to games, shopping websites, and crypto-wallets as they could be a specially crafted website.

Since the app for the Roamer malware had icons like that of Google Play Store and others, it is also urged that users maintain caution while accessing app stores from online websites.

It would be worth noting that the app store icon on the phishing website of Cloud Mining did not take users to the app store. Instead, it directly started the download of the malicious app from the hacker’s website while showing the app store icon.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: Android crypto malwareCloud mining scamCyble- blogRoamer banking trojanThe Cyber ExpressThe Cyber Express News
Previous Post

Yamaha Corporation of America Falls Victim to BlackByte Ransomware Attack

Next Post

Mystic Stealer Emerges on Dark Web, Offers Evasion Techniques and Data Exfiltration

Next Post
Mystic Stealer

Mystic Stealer Emerges on Dark Web, Offers Evasion Techniques and Data Exfiltration

Sectoral Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

UNC6783, BPO, Google Threat Intelligence Group, Okta, Help Desk, Phishing
Cyber News

UNC6783 Turns BPO Providers into Cyberattack Gateways

April 9, 2026
SOHO router
Firewall Daily

Russian Hackers Exploit SOHO Routers for DNS Hijacking Campaign

April 9, 2026
Signature Healthcare cyberattack
Firewall Daily

Signature Healthcare Cyberattack Causes Service Disruptions, Treatment Delays

April 9, 2026
Bitcoin Depot cyberattack
Cyber News

Bitcoin Depot Discloses $3.6 Million Crypto Theft Following System Breach

April 9, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information