Incidents

Brazilian Trojan Bankers – now on your Android Play Store!

It took some time but they’re finally here – Brazilian cybercriminals have started to target their attacks towards mobile banking users. This week we spotted the first Trojan banker targeting Brazilian users of Android devices. Two malicious applications meant to pass for apps from local Banks were hosted on Google Play.

en_generic_rgb_wo_60

According FEBRABAN (the local Federation of Banks), more than 6 million Brazilians are using mobile banking regularly, so it’s not surprising to find malware targeting mobile users. In fact, Brazil was crowned the country most attacked by banking malware in our Q3 threat evolution report:

Q3_2014_MW_Report_14This move by Brazilian bad guys was predictable and awaited as a natural development in the local malware scene. In 2012, we witnessed attacks using phishing pages in mobile format and now a bad guy using the name “Governo Federal” (Federal Government) was able to publish 2 malicious apps in the Play store:

3

Both apps used the name of two very popular public Brazilian Banks – the first app was published on October 31st and registered 80 installations. The second was published on November 10th and had only 1 installation.

To create the malicious app, the (lazy) bad guy decided to use “App Inventor”: a free platform that allows anyone to create their own mobile Android application, no technical knowledge required. The result is an app big in size and full of useless code. But both apps had the function to load the logos of the targeted Banks and open a frame – the phishing page programmed to capture the user’s credentials. Simple, but effective, as mobile banking users in Brazil still use single authentication, without tokens or OTPs, where only the account number and password are required.

6

The phishing pages of the targeted Banks were hosted on a hacked website. A good soul removed them and inserted an alert to the visitors stating: “Este é um aplicativo Falso, denuncie este app”, meaning “This is a fake app, please report it”. As a result, when the user downloads, installs and opens the fake banking app, this message is displayed inside, instead of the original phishing page:

9

We reported  both apps to Google, and they promptly removed them from the Play Store. We detect both apps as Trojan-Banker.AndroidOS.Binv.a (MD5s: 00C79B15E024D1B32075E0114475F1E2 and A18AC7C62C5EFD161039DB29BFDAA8EF) and we’re quite sure that these are only the first crude attempts of many more to come.

Thanks to my colleague Roman Unucheck for the valuable help in this case.

Brazilian Trojan Bankers – now on your Android Play Store!

Your email address will not be published. Required fields are marked *

 

  1. join

    good job

  2. AUGUSTINE CHRISTOPHER REBEIRO

    Thank you for all the effort put in to combat cyber crime and assist millions of us on the web by keeping us informed.

  3. Jo Goodwin

    Wow, you would think Google would be checking for this kind of behavior before posting it on Google Play.
    Who can we trust? Thanks for your hard work in keeping us safe.

Reports

Sunburst backdoor – code overlaps with Kazuar

While looking at the Sunburst backdoor, we discovered several features that overlap with a previously identified backdoor known as Kazuar. Our observations shows that Kazuar was used together with Turla tools during multiple breaches in past years.

Lazarus covets COVID-19-related intelligence

As the COVID-19 crisis grinds on, some threat actors are trying to speed up vaccine development by any means available. We have found evidence that the Lazarus group is going after intelligence that could help these efforts by attacking entities related to COVID-19 research.

Sunburst: connecting the dots in the DNS requests

We matched private and public DNS data for the SUNBURST-malware root C2 domain with the CNAME records, to identify who was targeted for further exploitation. In total, we analyzed 1722 DNS records, leading to 1026 unique target name parts and 964 unique UIDs.

What did DeathStalker hide between two ferns?

While tracking DeathStalker’s Powersing-based activities in May 2020, we detected a previously unknown implant that leveraged DNS over HTTPS as a C2 channel, as well as parts of its delivery chain. We named this new malware “PowerPepper”.

Subscribe to our weekly e-mails

The hottest research right in your inbox