The Xenomorph Android malware has upgraded with new capabilities, including an automated transfer system framework and the ability to steal login credentials from 400 banks. The malware was first discovered on the Google Play store in February 2022 with over 50,000 downloads. The latest version of the malware targets financial institutions in the United States, Spain, Turkey, Poland, Australia, Canada, Italy, Portugal, France, Germany, UAE, and India. "Some examples of targeted institutions include Chase, Citibank, American Express, ING, HSBC, Deutsche Bank, Wells Fargo, Amex, Citi, BNP, UniCredit, National Bank of Canada, BBVA, Santander, and Caixa. The list is too extensive to include here, but ThreatFabric has listed all targeted banks in the appendix of its report. Moreover, the malware targets 13 cryptocurrency wallets, including Binance, BitPay, KuCoin, Gemini, and Coinbase.