Malware

New Xenomorph Android malware targets European banks

0

A new malware named Xenomorph distributed through Google Play Store has infected over 50,000 Android devices to steal banking information.

Xenomorph, which is still in the early development stage, is targeting users of dozens of financial institutions in Spain, Portugal, Italy, and Belgium.

The researchers at fraud and cybercrime prevention company ThreatFabric who have analyzed Xenomorph, found code which is similar to Alien banking trojan. This suggests that the two threats are connected: either Xenomorph is Alien’s successor or a developer has been working on both of them.

The main aim of banking trojans like Xenomorph is to steal sensitive financial information, take over accounts, perform unauthorized transactions, and operators then sell the stolen data to interested buyers.

The Xenomorph malware entered the Google Play Store via generic performance-boosting applications such as the “Fast Cleaner”, which has over 50,000 installations.

These types of utilities are a lure used by banking Trojans like Alien, because there is always an interest in tools that promise to improve the performance of Android devices.

To evade rejection during the application review from the Play Store, Fast Cleaner is fetching the payload after installation, so the app is clean at submission time.

ThreatFabric recognized the application as a member of the “Gymdrop” dropper family that was first discovered in November 2021, and observed pushing payloads that pose as Google Play, Chrome, or Bitcoin management apps.

The complete functionality of Xenomorph’s is not known at the moment as the trojan is still under development. However, it represents a significant threat as it can fulfill its info-stealing purpose and it targets no less than 56 different European banks.

The malware can intercept notifications, log SMS, and use injections to perform overlay attacks, so it can already snatch credentials and one-time passwords used to protect banking accounts.

After its installation, the app first sends back a list of the installed packages on the infected device to load the suitable overlays.

To achieve the above, the malware requests the granting of Accessibility Service permissions upon installation, and then abuses the privileges to grant itself additional permissions as needed.

The malware may add next-level capabilities at any time, as only minor code implementations and modifications are required to activate extensive data siphoning functions.

According to ThreatFabric, Xenomorph is not a strong threat at the moment. In order to stay clear from Android malware that lurks in the Play Store, users are requested to avoid installing any apps that carry promises that are too good to be true. Also make sure to check other users’ reviews to avoid malicious apps.

Image Credits : Gear Bytes

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Threat actors stole at least $1.7M worth of NFTs from OpenSea users

Previous article

Expeditors operations impacted by cyber attack

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *