{"id":398717,"date":"2026-08-02T04:06:54","date_gmt":"2026-08-02T04:06:54","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=398717"},"modified":"2026-08-02T04:06:54","modified_gmt":"2026-08-02T04:06:54","slug":"night-dragon-rat-on-android-how-it-steals-banking-passwords-and-controls-your-phone","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/night-dragon-rat-on-android-how-it-steals-banking-passwords-and-controls-your-phone\/","title":{"rendered":"Night Dragon RAT on Android: How It Steals Banking Passwords and Controls Your Phone"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Night Dragon can turn an Android phone into a live surveillance device. Once installed, the malware can watch the screen, capture financial passwords and operate the phone while a fake system update hides what is happening.<\/p><div id=\"mwtad3340812207\" class=\"gas_fallback-ad_309684--placement_360520\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This is not a harmless utility or a dramatic antivirus warning. Night Dragon is a serious remote access trojan built for theft, spying and persistent control of infected Android devices.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/night-dragon-android-rat.png\" alt=\"Night Dragon Android RAT using hidden remote control and financial overlays\" class=\"wp-image-398710\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/night-dragon-android-rat.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/night-dragon-android-rat-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/night-dragon-android-rat-1024x683.png 1024w\" sizes=\"(max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">Night Dragon combines a disguised Android app, hidden remote control and convincing overlays designed to capture sensitive information.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad3035666906\" class=\"gas_fallback-ad_309746-ad_309691-placement_360521\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Night Dragon is a commercial Android remote access trojan, often shortened to RAT. It appeared in criminal channels as a more capable successor to Flying Eagle and continues the same basic strategy: persuade someone to sideload a convincing APK, request powerful Android permissions and then place the device under an operator&#8217;s control.<\/p><div id=\"mwtad3658995447\" class=\"gas_fallback-ad_381396-ad_309691-placement_360566\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The malware is dangerous because it does not rely on a single trick. Its operator can view the screen in real time, browse files, read text messages, open the photo gallery, activate the microphone and request images from the camera. A keylogger records what the victim types, while specialized overlays can imitate financial applications and collect passwords or payment details.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Night Dragon also abuses Android Accessibility Services. That permission is intended to help people operate their phones, but malware can misuse it to press buttons, swipe, open settings and approve actions. The attacker is therefore not limited to stolen information; they may be able to interact with the device almost as if they were holding it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stealth features make the infection harder to notice. The app can hide its launcher icon and display a black screen or fake system-update message while commands run underneath. A victim may believe the phone has temporarily frozen or is installing an update when the attacker is actually opening apps, changing settings or collecting data.<\/p><div id=\"mwtad1567506511\" class=\"gas_fallback-ad_309686-ad_309691-placement_360569\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Criminals can customize the app name, icon and installation lure, so there is no single Night Dragon icon to look for. The same malware may be presented as a government service, security update, delivery tool, finance app or another familiar-looking download. Packages and internal code can also be randomized to make each build look slightly different to scanners.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Threat type: Android remote access trojan<\/li><li>Main objective: surveillance, credential theft and remote device control<\/li><li>Key permissions: Accessibility, screen capture, files, camera, microphone and SMS<\/li><li>Common disguise: a customized app distributed outside Google Play<\/li><li>Highest-risk targets: banking, payment, wallet and messaging accounts<\/li><\/ul>\n\n\n\n<div id=\"mwtad3198748960\" class=\"gas_fallback-ad_309747-ad_309691-placement_360587\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How the Night Dragon RAT Infection Works<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1: The victim receives a convincing app link<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The attack usually starts with a message, social post or private channel that promotes an app the victim supposedly needs. The theme can change, but the download is hosted outside the official Google Play store.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The sender may claim the app provides access to a government service, account verification, a security update or a useful financial feature. Urgency and authority are used to discourage the victim from checking the source.<\/p><div id=\"mwtad2198944700\" class=\"gas_fallback-ad_381401-ad_309691-placement_360573\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2: A customized APK is installed<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The download is an Android Package Kit, or APK. Because it comes from an unofficial source, Android may ask the user to allow installations from that browser, file manager or messaging app.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Criminals can change the app&#8217;s visible name and icon before distributing it. Searching for one fixed Night Dragon filename is therefore unreliable; the installation source and requested permissions are more revealing.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3: The app requests powerful permissions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Night Dragon attempts to obtain access to features such as Accessibility Services, notifications, storage, the microphone, the camera and screen capture. A deceptive prompt may claim these permissions are needed for verification or normal operation.<\/p><div id=\"mwtad2620194228\" class=\"gas_fallback-ad_381404-ad_309691-placement_381406\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Accessibility access is especially serious. It can let the malware observe interface content and simulate taps or swipes, giving the attacker a path around security prompts that would otherwise require physical interaction.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4: The icon disappears and a control channel opens<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After installation, the malicious app may remove its icon from the launcher. It then contacts a command server and registers the phone with information that helps the operator identify and control it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Removing the icon does not uninstall the app. The malicious package can remain active in the background, and it may still appear under Settings even when it is absent from the home screen.<\/p><div id=\"mwtad2651058439\" class=\"gas_fallback-ad_360582-ad_309691-placement_360581\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9971336976\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Step 5: The attacker spies on the phone and captures credentials<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The operator can view the screen, read SMS messages, inspect photos and files, listen through the microphone and obtain camera footage. Keylogging and financial overlays are used to collect passwords, PINs, wallet phrases and payment information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an account uses SMS verification, access to messages may expose one-time codes. Combined with a stolen password, that can allow the attacker to sign in or approve a transaction before the victim understands what happened.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 6: A fake update screen hides remote activity<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Night Dragon can cover the display with a black screen or fake system-update page. Behind that cover, the attacker may open apps, change settings, transfer files or attempt financial actions.<\/p><div id=\"mwtad2809034553\" class=\"gas_fallback-ad_360567-ad_309691-placement_360771\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6224621518\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Unexpected update screens, repeated permission prompts, unusual battery drain and a phone that seems active while untouched should be treated as warning signs, particularly after a sideloaded app was installed.<\/p>\n\n\n\n<div id=\"mwtad871266793\" class=\"gas_fallback-ad_309748-ad_309691-placement_360588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">What Night Dragon Can Steal or Control<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An infected phone can expose far more than one password. Modern Android devices hold identity documents, private conversations, authentication codes and access to financial services, making remote control especially damaging.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Banking, payment and cryptocurrency-wallet credentials<\/li><li>Passwords, PINs and information typed into apps<\/li><li>SMS messages, including one-time verification codes<\/li><li>Photos, videos, documents and downloaded files<\/li><li>Live screen content and app activity<\/li><li>Microphone audio and camera footage<\/li><li>Contacts, device details and other account information<\/li><\/ul>\n\n\n\n<div id=\"mwtad757387063\" class=\"gas_fallback-ad_318930-ad_309691-placement_360589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Warning Signs of a Night Dragon Infection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No single symptom proves the phone has Night Dragon, but several changes appearing after an unofficial app installation deserve immediate attention.<\/p><div id=\"mwtad3562344486\" class=\"gas_fallback-ad_360571-ad_309691-placement_360772\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5867729999\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<ul class=\"wp-block-list\"><li>A recently installed app disappears from the launcher<\/li><li>An unfamiliar app has Accessibility or device-administrator access<\/li><li>The screen turns black or shows unexplained system updates<\/li><li>The camera or microphone indicator appears unexpectedly<\/li><li>The phone becomes hot, slow or drains its battery unusually fast<\/li><li>Mobile data use increases without a clear reason<\/li><li>Banking or payment apps display unusual login screens<\/li><li>Security settings change or prompts appear without your action<\/li><\/ul>\n\n\n\n<div id=\"mwtad2284249122\" class=\"gas_fallback-ad_381388-ad_309691-placement_381390\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">What to Do If You Installed a Suspicious Android App<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Disconnect the phone before investigating<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Turn on airplane mode and disable Wi-Fi and Bluetooth. This interrupts the attacker&#8217;s live connection and can reduce further data theft while you inspect the device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use a different, trusted device for banking or password changes. A phone that may be keylogged should not be used to create replacement passwords.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Revoke dangerous permissions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Open Android Settings and review Accessibility, Device admin apps, notification access, install unknown apps, VPN and screen-capture permissions. Disable access for the suspicious app before trying to remove it.<\/p><div id=\"mwtad2925527046\" class=\"gas_fallback-ad_360576-ad_309691-placement_360773\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6594472392\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Menu names vary by phone manufacturer. If the malicious app blocks Settings or immediately closes the page, restart the phone in Safe Mode and try again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Uninstall the suspicious package<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check Settings under Apps or Application management, including recently installed apps that have generic names or no visible icon. Clear administrator privileges first if the Uninstall button is disabled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also remove the downloaded APK from the Downloads folder and turn off permission to install unknown apps for the browser or messenger that delivered it.<\/p><div id=\"mwtad2538177808\" class=\"gas_fallback-ad_360583-ad_309691-placement_360774\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8849826992\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Scan the Android device<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A reputable mobile security scan can identify remaining components and other unwanted software installed with the same package.<\/p>\n\n\n<p>Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don&#8217;t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.<\/p>\n\n\n<ol class=\"wp-block-list\">\n<li>\n<p class=\"mwt_quick_overview\">Download Malwarebytes for Android.<\/p>\n<p>You can download <strong>Malwarebytes for Android<\/strong> by clicking the link below.<\/p>\n<figure><img decoding=\"async\" class=\"alignleft size-full wp-image-81150 mwt_product_icon_logo\" title=\"Malwarebytes Icon\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2018\/06\/Malwarebytes-LOGO.png\" alt=\"Malwarebytes Logo\" width=\"40\" height=\"40\"\/><\/figure><div class=\"mwt_download_box\"><strong><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=org.malwarebytes.antimalware&#038;hl=en\" target=\"_blank\" rel=\"noopener noreferrer\">MALWAREBYTES FOR ANDROID DOWNLOAD LINK<\/a><\/strong><br \/><em>(The above link will open a new page from where you can download Malwarebytes for Android)<\/em><\/div>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Install Malwarebytes for Android on your phone.<\/p>\n<p>In the Google Play Store, tap &#8220;<strong>Install<\/strong>&#8221; to install Malwarebytes for Android on your device.<\/p>\n<figure><img decoding=\"async\" class=\"alignnone size-full wp-image-106940\" title=\"Tap Install to install Malwarebytes for Android\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Google-Play-App.jpg\" alt=\"Tap Install to install Malwarebytes for Android\" width=\"292\" height=\"580\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Google-Play-App.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Google-Play-App-151x300.jpg 151w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/figure><p><\/p>\n<p>When the installation process has finished, tap &#8220;<strong>Open<\/strong>&#8221; to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106941\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Open-App.jpg\" alt=\"Malwarebytes for Android - Open App\" width=\"292\" height=\"578\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Open-App.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Open-App-152x300.jpg 152w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Follow the on-screen prompts to complete the setup process<\/p>\n<p>When Malwarebytes will open, you will see the <em>Malwarebytes Setup Wizard<\/em> which will guide you through a series of permissions and other setup options.<br \/>This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106944\" title=\"Malwarebytes Setup Screen 1\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-1.jpg\" alt=\"Malwarebytes Setup Screen 1\" width=\"292\" height=\"577\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-1.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-1-152x300.jpg 152w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><br \/>Tap on &#8220;<strong>Got it<\/strong>&#8221; to proceed to the next step.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106945\" title=\"Malwarebytes Setup Screen 2\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-2.jpg\" alt=\"Malwarebytes Setup Screen 2\" width=\"292\" height=\"580\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-2.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-2-151x300.jpg 151w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><br \/>Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on &#8220;<strong>Give permission<\/strong>&#8221; to continue.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106946\" title=\"Malwarebytes Setup Screen 3\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-3.jpg\" alt=\"Malwarebytes Setup Screen 3\" width=\"292\" height=\"570\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-3.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-3-154x300.jpg 154w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><br \/>Tap on &#8220;Allow&#8221; to permit Malwarebytes to access the files on your phone.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106947\" title=\"Malwarebytes Setup Screen 4\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-7.jpg\" alt=\"Malwarebytes Setup Screen 4\" width=\"292\" height=\"573\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-7.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Setup-Wizard-7-153x300.jpg 153w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Update database and run a scan with Malwarebytes for Android<\/p>\n<p>You will now be prompted to update the Malwarebytes database and run a full system scan.<\/p>\n<figure><img decoding=\"async\" class=\"alignnone size-full wp-image-106939\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Fix-Issues.jpg\" alt=\"Malwarebytes fix issue\" width=\"292\" height=\"579\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Fix-Issues.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Fix-Issues-151x300.jpg 151w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/figure><p><\/p>\n<p>Click on &#8220;<strong>Update database<\/strong>&#8221; to update the Malwarebytes for Android definitions to the latest version, then click on &#8220;<strong>Run full scan<\/strong>&#8221; to perform a system scan.<\/p>\n<figure><img decoding=\"async\" class=\"alignnone size-full wp-image-106948\" title=\"Update database and run Malwarebytes scan\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Update-Run-Scan.jpg\" alt=\"Update database and run Malwarebytes scan on phone\" width=\"291\" height=\"575\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Update-Run-Scan.jpg 291w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Update-Run-Scan-152x300.jpg 152w\" sizes=\"(max-width: 291px) 100vw, 291px\" \/><\/figure><p><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Wait for the Malwarebytes scan to complete.<\/p>\n<p>Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106943\" title=\"Malwarebytes scanning phone for malware\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Scanning-for-Malware.jpg\" alt=\"Malwarebytes scanning Android for Vmalware\" width=\"292\" height=\"579\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Scanning-for-Malware.jpg 292w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Scanning-for-Malware-151x300.jpg 151w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Click on &#8220;Remove Selected&#8221;.<\/p>\n<p>When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the &#8220;<strong>Remove Selected<\/strong>&#8221; button.<br \/><img decoding=\"async\" class=\"alignnone size-full wp-image-106942\" title=\"Tap on the Remove button to get rid of malware\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Removing-Malware.jpg\" alt=\"Remove malware from your phone\" width=\"760\" height=\"600\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Removing-Malware.jpg 760w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2020\/05\/Malwarebytes-for-Android-Removing-Malware-300x237.jpg 300w\" sizes=\"(max-width: 760px) 100vw, 760px\" \/><\/p>\n<\/li>\n\n\n\n<li>\n<p class=\"mwt_quick_overview\">Restart your phone.<\/p>\n<p>Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.<\/p>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Secure important accounts from a clean device<\/h3>\n\n\n\n<div id=\"mwtad3341369429\" class=\"gas_fallback-ad_360584-ad_309691-placement_360775\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3952847241\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p class=\"wp-block-paragraph\">Change the passwords for email, banking, payment, social-media and cryptocurrency accounts. Sign out other sessions, replace exposed recovery codes and contact financial providers if the infected phone was used for transactions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tell your mobile carrier if SMS codes or the phone number may have been exposed. Ask whether a SIM or account PIN should be changed, and watch for unauthorized number-porting requests.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Consider a factory reset when trust cannot be restored<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If remote-control symptoms continue, the app cannot be removed or sensitive accounts were accessed, back up only irreplaceable personal files and perform a factory reset. Do not restore the suspicious APK or an unverified full-device backup.<\/p>\n\n\n\n<div id=\"mwtad611383791\" class=\"gas_fallback-ad_381392-ad_309691-placement_381395\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How to Avoid Android RATs<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Install apps from Google Play or another trusted official store<\/li><li>Do not enable unknown-app installation for links received in messages<\/li><li>Treat requests for Accessibility access as a high-risk decision<\/li><li>Check the developer, download history and permissions before installing<\/li><li>Keep Android, Google Play system updates and security software current<\/li><li>Use unique passwords and app-based or hardware security keys where available<\/li><li>Remove apps you no longer use and review special permissions regularly<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Is Night Dragon available in Google Play?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The known distribution method relies on disguised, sideloaded APK files rather than a normal verified Play Store installation. A fake listing or lookalike download page should not be treated as proof of legitimacy.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can Night Dragon infect an iPhone?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Night Dragon is designed for Android. The APK files used by the campaign do not run on iOS, although iPhone users can still face unrelated phishing and account-theft attempts.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does deleting the app icon remove the malware?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. Night Dragon can hide its launcher icon while remaining installed. The package must be found in Android Settings, stripped of elevated permissions and properly uninstalled.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can a fake update screen be trusted?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A genuine Android update should be initiated and verified through Settings. An unexpected full-screen update immediately after installing an unofficial app can be a cover for malicious activity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Bottom Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Night Dragon is a confirmed Android remote access trojan, not a questionable utility. It can hide on the phone, capture financial passwords, read messages, activate sensors and let a criminal operate the device remotely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you installed a suspicious APK and granted it Accessibility access, disconnect the phone immediately. Remove the app, run a security scan and protect financial and email accounts from a separate clean device.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Night Dragon is an Android remote access trojan that can hide its icon, record the screen, steal financial passwords and secretly control an infected phone.<\/p>\n","protected":false},"author":50,"featured_media":398710,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ai_generated_summary":"","footnotes":""},"categories":[2836,2728],"tags":[],"class_list":["post-398717","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-removal-and-popup-scam-alerts","category-trojans","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=398717"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398717\/revisions"}],"predecessor-version":[{"id":398718,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398717\/revisions\/398718"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/398710"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=398717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=398717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=398717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}