Malware

BRATA android malware is evolving into a persistent threat

0

An Android banking trojan famous for wiping smartphones to cover its tracks has got several new features to improve its ability at phishing online-banking credentials, intercepting SMS two-factor authentication codes etc.

The BRATA or the ‘Brazilian Remote Access Tool, Android’ has been around since at least 2019, initially as spyware and then later became a banking trojan.

The researchers at an Italian cybersecurity firm, Cleafy discovered last year that BRATA’s makers had started abusing Android’s factory reset to prevent victims from discovering, reporting and preventing unauthorized wire transfers.

The factory reset was executed after a successful illicit wire transfer or when the malware detected analysis by installed security software.

BRATA targeted customers from Brazilian banks only, but not it has started targeting customers of UK, Spanish and British banking brands as well.

The malware was spread through fraudulent SMS messages pretending to be from a target’s bank, but it contained a link that would download BRATA.

The researchers claim that the new variant spreading across Europe features new phishing pages mimicking targeted banks, new methods of acquiring permissions to access GPS location data, and new ways to send and receive SMS, and gain device management permissions. It also gained the ability to sideload a second-stage piece of malware from its command and control server to perform event logging.

The combination of the phishing pages and the ability to receive and read the victim’s SMS could be used to take over a victim’s bank account.

The researchers also discovered a related SMS-stealing app that shared some code with the BRATA malware. The malicious app asks the user to change the default messaging app to the malicious one in order to intercept incoming messages, including two-factor authentication codes or one-time passcodes.

The threat actors behind BRATA target a specific financial institution at a time, and change their focus only once the targeted victim starts to implement consistent countermeasures against them. Later on they move away from the spotlight, and then come out with a different target and strategies of infections.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

QNAP NAS devices hit by eCh0raix ransomware attacks

Previous article

Flagstar Bank discloses data breach impacting 1.5 million customers

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *