• About Us
  • Privacy Policy
  • Contact
Mortgage Insurance Center
  • Home
  • Mortgages
  • Health Insurance
  • Home Insurance
  • Life insuranace
  • Finance Laws
    • Banking Laws
    • Assets
    • Interest Rate
    • Loans
No Result
View All Result
  • Home
  • Mortgages
  • Health Insurance
  • Home Insurance
  • Life insuranace
  • Finance Laws
    • Banking Laws
    • Assets
    • Interest Rate
    • Loans
No Result
View All Result
Mortgage Insurance Center
No Result
View All Result
Home Banking Laws

A New Android Banking Trojan Spotted in the Wild

by Staff
June 19, 2022
in Banking Laws
0
A New Android Banking Trojan Spotted in the Wild
0
SHARES
4
VIEWS
Share on FacebookShare on Twitter

[ad_1]

Android Banking Trojan

A new strain of Android malware has been spotted in the wild targeting online banking and cryptocurrency wallet customers in Spain and Italy, just weeks after a coordinated law enforcement operation dismantled FluBot.

The information stealing trojan, codenamed MaliBot by F5 Labs, is as feature-rich as its counterparts, allowing it to steal credentials and cookies, bypass multi-factor authentication (MFA) codes, and abuse Android’s Accessibility Service to monitor the victim’s device screen.

MaliBot is known to primarily disguise itself as cryptocurrency mining apps such as Mining X or The CryptoApp that are distributed via fraudulent websites designed to attract potential visitors into downloading them.

CyberSecurity

It also takes another leaf out of the mobile banking trojan playbook in that it employs smishing as a distribution vector to proliferate the malware by accessing an infected smartphone’s contacts and sending SMS messages containing links to the malware.

“MaliBot’s command-and-control (C2) is in Russia and appears to use the same servers that were used to distribute the Sality malware,” F5 Labs researcher Dor Nizar said. “It is a heavily modified re-working of the SOVA malware, with different functionality, targets, C2 servers, domains, and packing schemes.”

Android Banking Trojan

SOVA (meaning “Owl” in Russian), which was first detected in August 2021, is notable for its ability to conduct overlay attacks, which work by displaying a fraudulent page using WebView with a link provided by the C2 server should a victim open a banking app included in its active target list.

Some of the banks targeted by MaliBot using this approach include UniCredit, Santander, CaixaBank, and CartaBCC. The Mining X campaign is believed to have commenced on April 11, with the MaliBot malware first discovered a week later around April 18, Nizar told The Hacker News in a statement.

Accessibility Service is a background service running in Android devices to assist users with disabilities. It has long been leveraged by spyware and trojans to capture the device contents and intercept credentials entered by unsuspecting users on other apps.

CyberSecurity

Besides being able to siphon passwords and cookies of the victim’s Google account, the malware is designed to swipe 2FA codes from the Google Authenticator app as well as exfiltrate sensitive information such as total balances and seed phrases from Binance and Trust Wallet apps.

Android Banking Trojan

What’s more, Malibot is capable of weaponizing its access to the Accessibility API to defeat Google’s two-factor authentication (2FA) methods, such as Google prompts, even in scenarios where an attempt is made to sign in to the accounts using the stolen credentials from a previously unknown device.

“The versatility of the malware and the control it gives attackers over the device mean that it could, in principle, be used for a wider range of attacks than stealing credentials and cryptocurrency,” the researchers said.

“In fact, any application which makes use of WebView is liable to having the users’ credentials and cookies stolen.”

“MaliBot is a clear example of how diverse the mobile banking trojan threat is to banks and their customers,” Richard Melick, director of threat reporting at Zimperium, said, adding “malicious actors are constantly evolving their tactics to reach their targets.”

“Mobile banking apps are proven, high-value targets with little security in place to prevent theft. Financial institutions need to implement better security controls and active threat detections to stay ahead of fast-evolving threats like these.”



[ad_2]

Source link

Previous Post

Shark Tank’s Kevin O’Leary Explains Why Wipeout of Large Digital Asset Firms Is Great for Crypto

Next Post

Nathalie Sénéchault to be appointed Chief Financial Officer of Atos

Next Post

Nathalie Sénéchault to be appointed Chief Financial Officer of Atos

Popular Posts

Ajanta Pharma : Newspaper Advertisements
Life insuranace

Taiming Assurance Broker : Announcement on behalf of the major subsidiary Link-Aim Life Insurance Broker Co.,LTD. to distribute dividends.

by Staff
July 28, 2022
0

Close Provided by: TAIMING ASSURANCE BROKER CO.,LTD. SEQ_NO 4 Date of...

Read more

Taiming Assurance Broker : Announcement on behalf of the major subsidiary Link-Aim Life Insurance Broker Co.,LTD. to distribute dividends.

20% interest rate on credit cards! Here’s how to avoid paying those high rates :: WRAL.com

Sens. Murphy, Blumenthal, Colleagues Reintroduce the Behavioral Health Coverage Transparency Act – InsuranceNewsNet

$1 billion in loans still available for agricultural funding in Ohio

How Long Do Car Accidents Stay on Your Record?

Rocket Mortgage Classic Wagers: Pick To Finish Top-10

Load More

Popular Posts

The perks and pitfalls of adjustable-rate mortgages in 2022

by Staff
June 13, 2022
0

Ajanta Pharma : Newspaper Advertisements

Taiming Assurance Broker : Announcement on behalf of the major subsidiary Link-Aim Life Insurance Broker Co.,LTD. to distribute dividends.

by Staff
July 28, 2022
0

Propy introduces blockchain title and escrow service

Propy introduces blockchain title and escrow service

by Staff
May 26, 2022
0

Ajanta Pharma : Newspaper Advertisements

Taiming Assurance Broker : Announcement on behalf of the major subsidiary Link-Aim Life Insurance Broker Co.,LTD. to distribute dividends.

July 28, 2022

20% interest rate on credit cards! Here’s how to avoid paying those high rates :: WRAL.com

July 28, 2022
Edelweiss General Insurance launches India’s first on-demand, mobile telematics-based comprehensive motor insurance – SWITCH

Sens. Murphy, Blumenthal, Colleagues Reintroduce the Behavioral Health Coverage Transparency Act – InsuranceNewsNet

July 28, 2022

Categories

  • Assets
  • Banking Laws
  • Finance Laws
  • Health Insurance
  • Home Insurance
  • Interest Rate
  • Life insuranace
  • Loans
  • Mortgages

Tags

home loans mortgage personal loan
  • Privacy Policy
  • contact us

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • About Us
  • contact us
  • Home
  • Home 2
  • Home 3
  • Privacy Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.