Xenomorph malware has reemerged in a new distribution campaign, and has targeted over 30 US banks along with various financial institutions worldwide.
According to the cybersecurity analysts from ThreatFabric, who recently uncovered this resurgence, the campaign relies on deceptive phishing webpages posing as a Chrome update to trick victims into downloading malicious APKs.
Xenomorph was first spotted in February 2022 and this malware is known for using overlays to capture personally identifiable information (PII) such as usernames and passwords. Notably, it features a sophisticated automated transfer system (ATS) engine, enabling a wide range of actions and modules, enhancing its adaptability.
The latest campaign has seen a geographical expansion, with thousands of Xenomorph downloads recorded in Spain and the United States.
Xenomorph has added new capabilities to its arsenal, including an anti-sleep feature, a “mimic” mode to avoid detection and the ability to simulate touch actions. The malware’s targets include Spain, Portugal, Italy, Canada, Belgium, numerous US financial institutions and cryptocurrency wallets.
Xenomorph is being distributed alongside powerful desktop stealers and it has now been offered as a Malware-as-a-Service (MaaS) for use in conjunction with other malicious software families.
According to an advisory published by ThreatFabric, this resurgence underscores the persistent efforts of cyber-criminals to maximize their profits.
Xenomorph maintains its status as an extremely dangerous Android Banking malware, featuring a very versatile and powerful ATS engine, with multiple modules already created, with the idea of supporting multiple manufacturer’s devices.














Comments