UBEL was an Android malware botnet promoted in 2021, and Cleafy researchers found code indicators linking it to the earlier Oscorp malware. That supports a shared-codebase connection, not proof that the same people operated both. The available reporting documents activity in 2021; it does not establish whether UBEL remains active in October 2026.
Why researchers linked UBEL to Oscorp
Cleafy reported that Oscorp activity appeared in early 2021, then seemed to stop. New samples surfaced around May and June as a botnet called UBEL was being advertised on hacking forums. Researchers identified multiple indicators connecting the samples to the same codebase and suggested UBEL could be a fork or rebrand, potentially involving affiliates. Those are interpretations of technical evidence, not a confirmed identity for the malware’s authors or operators. Cleafy’s 2021 analysis is the primary account of that relationship.
The phrase “new Oscorp” therefore describes the reported technical lineage, not a verified handover between known criminal groups. The Hacker News reported that UBEL was advertised for $980 in 2021; that was a historical asking price, not a validated sale or a current market price. The Hacker News report is secondary coverage.
How the reported Android attack worked
The reports describe social engineering as part of the attack: victims could be urged to install an app and grant it intrusive permissions. In predecessor Oscorp activity, Cleafy analyzed a campaign involving smishing followed by a phone call in which an impostor posing as a bank operator persuaded the victim to enable access. Attackers then used the compromised device during fraudulent transfers. Cleafy noted this could avoid a bank’s signal that a new device had been enrolled. This is an analyzed campaign, not evidence that every UBEL infection followed the same sequence.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- POWERFUL, LIGHTNING-FAST ANTIVIRUS: Protects your computer from viruses and malware through the cloud; Webroot scans faster, uses fewer system resources and safeguards your devices in real-time by identifying and blocking new threats
- IDENTITY THEFT PROTECTION AND ANTI-PHISHING: Webroot protects your personal information against keyloggers, spyware, and other online threats and warns you of potential danger before you click
- ALWAYS UP TO DATE: Webroot scours 95% of the internet three times per day including billions of web pages, files and apps to determine what is safe online and enhances the software automatically without time-consuming updates
- SUPPORTS ALL DEVICES: Compatible with PC, MAC, Chromebook, Mobile Smartphones and Tablets including Windows, macOS, Apple iOS and Android
- NEW SECURITY DESIGNED FOR CHROMEBOOKS: Chromebooks are susceptible to fake applications, bad browser extensions and malicious web content; close these security gaps with extra protection specifically designed to safeguard your Chromebook
Why Accessibility access mattered
Android Accessibility services are designed to help people interact with their devices. Malware with this access can abuse it to observe or interact with what appears on screen and, in some cases, capture what a user types. CERT-AGID’s 2021 account of Oscorp describes this kind of abuse to support credential theft through phishing pages or injected screens, and notes potential audio or video capture. Treat those details as predecessor context rather than assuming every capability was present in every UBEL sample. CERT-AGID’s Oscorp report covers that context.
Capabilities described in the reports
Cleafy documented Oscorp capabilities including SMS sending, interception and deletion; phone calls; keylogging; and remote control using WebRTC and Android Accessibility Services. Its report said overlay attacks targeted more than 150 mobile applications. That figure describes the reported scope of Oscorp overlays, not victims or UBEL’s current reach.
Rank #2
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
The Hacker News’ secondary account of UBEL reported that it could read and send SMS, record audio, install or delete applications, start after boot, and use Accessibility abuse to obtain credentials and two-factor codes. It also described data exfiltration to a remote server and WebRTC interaction. These are reported capabilities; they should not be read as a guarantee that every sample had all of them.
Is UBEL still active?
The cited reporting establishes that UBEL was promoted and analyzed in 2021. It does not provide an authoritative current infection count, prevalence estimate, financial-loss total, or evidence that the botnet remains active in October 2026. “Active in the wild” belongs to the original 2021 reporting context, not a verified statement about today’s threat level. An unfamiliar app or suspicious account activity still warrants a careful security check, but it cannot by itself identify UBEL.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
- SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
- ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
- ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.
What to do if you suspect an Android app is malicious
Start with suspicious apps and account activity, then work through Google’s recommended protections and recovery options. Menu names and device behavior can vary by Android version and manufacturer.
- Check the app and its permissions. Be wary of an app installed from a link in an unsolicited message or outside Google Play, especially if its ordinary purpose does not explain why it needs Accessibility access. CERT-AGID’s Oscorp account describes abuse of that permission; Google also warns that apps from unknown sources can put a device and personal information at risk.
- Keep Play Protect enabled. Google says, “Google Play Protect checks your apps and devices for harmful behavior.” It scans apps, can warn about potentially harmful apps, and may disable or remove them. See Google Play Protect help.
- Update Android and remove apps you do not trust. Install available Android and security updates, and uninstall apps you did not intentionally install or no longer trust.
- Review Google Account security. Check the account for unfamiliar activity and follow Google’s account-security guidance if anything looks wrong.
- Escalate if signs persist. Google’s Android malware guidance says a device reset may be necessary, or you may need help from the device manufacturer. It does not offer a UBEL-specific one-click removal method. Follow the current steps in Google’s Android malware removal guidance.
These response steps address general Android malware risk; they do not confirm that a device is infected with UBEL.
Quick Recap
Best Value
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Rank #4
- STAY PROTECTED EVERYWHERE you go, at home, in a café, at the airport—everywhere—on ALL YOUR DEVICES, with cloud-based protection against viruses & other online threats
- Webroot PASSWORD MANAGER by Last Pass creates, encrypts, and saves all your passwords, so you only have to remember one.
- As the #1 TRUSTED PROVIDER OF THREAT INTELLIGENCE, you know you’re in good hands. Stay safe from viruses, ransomware, phishing, and more.
- Webroot SOFTWARE UPDATES ITSELF AUTOMATICALLY, so you always have the most current protection without lifting a finger—and updates happen in the background so they won’t slow you down.
- PREMIUM FEATURES: Encrypts & protects passwords and account information for all your devices so you can stay protected wherever you are.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

