An Android banking trojan named SpyNote has been targeting financial institutions in Europe as part of an aggressive campaign detected in June and July 2023.
According to Italian cybersecurity firm Cleafy, an aggressive campaign utilizing SpyNote has been observed, posing significant threats to the security of bank customers.
The spyware is distributed through email phishing or smishing campaigns and the fraudulent activities are executed with a combination of remote access trojan (RAT) capabilities and vishing attack.
SpyNote, also called SpyMax, is similar to other Android banking Trojans and it exploits Accessibility services and various Android permissions to gather sensitive data from infected devices. The malware acts as spyware and also perform bank fraud.
The infection chain begins with a bogus SMS message urging users to install a banking app by clicking on the accompanying link, redirecting the victim to the legitimate TeamViewer QuickSupport app available on the Google Play Store. However, this is the initial step to gain remote access to the victim’s device.
TeamViewer is used as a conduit to gain remote access to the victim’s phone, and stealthily install the malware. The various kinds of information collected by SpyNote include geolocation data, keystrokes, screen recordings, and SMS messages to bypass SMS-based two-factor authentication (2FA).
To evade detection and analysis, SpyNote employs various defense evasion techniques, such as code obfuscation, anti-emulator controls and the prevention of manual removal by hiding the application icon.
Cleafy concluded that the aggressive and extensive nature of the SpyNote campaign indicates that threat actors will likely continue to exploit this spyware’s multiple functionalities to perpetrate bank fraud.
Financial institutions and users are recommended to remain vigilant against phishing and smishing attempts and regularly update their security measures to defend against these evolving threats.
Image Credits : HackRead

















Comments