Malware

FjordPhantom Android malware targets Banking apps

0

Security researchers have discovered a new Android malware, known as FjordPhantom, that has been targeting users in Southeast Asian countries like Indonesia, Thailand, and Vietnam since early September 2023.

The malware notable for its elusive nature and covert spreading tactics was initially reported in early September in Southeast Asia with potential activity in Singapore and Malaysia. It employs a combination of app-based tactics and social engineering to target banking customers.

Promon’s Security Research team said it received a sample from an affected customer. It was observed that one FjordPhantom attack resulted in a substantial loss of 10m Thai Baht (approximately $280,000).

The malware primarily spreads through email, SMS and messaging apps, prompting users to download that looks like their bank’s legitimate app.

Then a social engineering attack is initiated, often supported by a call center, guiding users through app execution. This enables attackers to monitor user actions, potentially guiding transactions or stealing credentials.

The main feature of the malware includes the use of virtualization, leveraging open source code from GitHub to embed a virtualization solution and hooking framework. By loading apps into virtual containers, FjordPhantom breaks the Android sandbox, allowing different apps to access each other’s files and memory.

FjordPhantom embeds the APK of a specific banking app it targets, launching it within a virtual container without the user’s knowledge. This method allows the malware to inject additional code, including its own and the hooking framework, tailored for modular attacks on various banking apps.

In order to tackle this threat, Promon urged end users to be cautious when downloading apps from untrusted sources and outside the primary app stores.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Hackers breach Israeli Defense Ministry

Previous article

Russian developer of Trickbot malware pleads guilty

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *