The research, conducted by Zimperium’s zLabs threat research team, expands on previously identified TaxiSpy samples by uncovering additional infrastructure, artifacts, and indicators tied to the malware’s command-and-control (C2) operations. These extended IOCs provide security teams with greater visibility into the malware’s activity and improve the ability to detect and block infections across enterprise mobile environments.
TaxiSpy is designed to compromise Android devices and steal sensitive information, including banking credentials and financial data. Like many modern mobile banking trojans, it leverages malicious applications and remote command-and-control infrastructure to maintain persistence, monitor user activity, and enable attackers to conduct fraudulent transactions.
The newly released indicators help organizations identify suspicious domains, network activity, and malware artifacts associated with TaxiSpy campaigns. By publishing these IOCs, Zimperium aims to strengthen industry collaboration and enable security teams to proactively defend against evolving mobile threats.
“Mobile banking malware continues to evolve in sophistication, often expanding its infrastructure and capabilities after initial discovery,” said Nico Chiaraviglio, Chief Scientist at Zimperium. “By releasing extended indicators of compromise for TaxiSpy, we’re providing the broader security community with actionable intelligence that helps identify and disrupt these campaigns before they can impact users or organizations.”
Mobile threats targeting financial applications are increasing as cybercriminals focus on smartphones as a primary attack surface. Banking trojans typically exploit device permissions, overlays, and remote command capabilities to intercept credentials and perform fraudulent transactions.
Security teams are encouraged to review the published IOCs and integrate them into detection systems, threat intelligence platforms, and incident response workflows to better identify potential TaxiSpy activity.






