• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

Overlay Attack

Also known as: Screen Overlay Attack, GUI Input Capture, Phishing Overlay, Activity Hijacking, Window Overlay, Banking Overlay, App Overlay Attack

COMPROMISEMITRE ATT&CK: GUI Input Capture technique (T1417.002) documenting overlay attacks

Malware displays fake login screens over legitimate banking or payment apps to capture credentials.

Common attack flows

How it fits in a scam

This technique shows up duringCOMPROMISE

Before

  • Supply Chain CompromiseCOMPROMISE
  • Malicious App InstallationCOMPROMISE
  • Phishing EmailDELIVERY
  • SmishingDELIVERY
  • +3 more

After

  • Credential TheftCOMPROMISE
  • Account TakeoverEXPLOITATION
  • Credential TheftCOMPROMISE

Defense

How to defend against this

How to spot it

  • Review Settings > Apps > Special app access > Display over other apps for unknown apps with overlay permission
  • Unexpected login prompts appearing when banking app not deliberately opened
  • Login screen with different visual styling or subtle differences from normal app UI
  • Apps requesting Accessibility Services or SYSTEM_ALERT_WINDOW permission without clear need
  • Google Play Protect disabled without user action
  • Unusual device lag or battery drain from background overlay monitoring
  • Credential prompts appearing outside normal app workflows

Tools you can use

  • Mobile Security AppCost low · Effect high
  • Software UpdatesCost low · Effect high
  • Antivirus SoftwareCost low · Effect medium

Steps you can take

  • App Permission ReviewCost low · Effect medium
  • Official App Store OnlyCost low · Effect medium

Further reading

  • MITRE ATT&CK

    GUI Input Capture technique (T1417.002) documenting overlay attacks

  • MITRE ATT&CK

    Anubis banking trojan targeting 250+ apps with overlays

  • MITRE ATT&CK

    Cerberus banking trojan with overlay attack capabilities

  • Kaspersky

    2023 mobile banking trojan statistics and trends

Related techniques

Variants

  • Malware

Same stage

  • Credential Theft
  • SIM Swap
  • MFA Fatigue Attack
  • Clipboard Hijacking
  • Malicious App Installation
  • +8 more

Similar defense

  • Remote Access Tool
  • Tech Support Scam
  • Malvertising
  • Smishing
  • Poisoned Software
  • +10 more