Home Security Malicious Google Play Retailer App Noticed Distributing Xenomorph Banking Trojan

Malicious Google Play Retailer App Noticed Distributing Xenomorph Banking Trojan

by crpt os


Google has removed two new malicious dropper apps that have been detected on the Play Store for Android, one of which posed as a lifestyle app and was caught distributing the Xenomorph banking malware.

“Xenomorph is a trojan that steals credentials from banking applications on users’ devices,” Zscaler ThreatLabz researchers Himanshu Sharma and Viral Gandhi said in an analysis published Thursday.

“It is also capable of intercepting users’ SMS messages and notifications, enabling it to steal one-time passwords and multi-factor authentication requests.”

The cybersecurity firm said it also found an expense tracker app that exhibited similar behavior, but noted that it couldn’t extract the URL used to fetch the malware artifact.

Xenomorph Banking Trojan

The two malicious apps are as follows –

  • Todo: Day manager (com.todo.daymanager)
  • 経費キーパー (com.setprice.expenses)

Both the apps function as a dropper, meaning the apps themselves are harmless and are a conduit to retrieve the actual payload, which, in the case of Todo, is hosted on GitHub.

CyberSecurity

Xenomorph, first documented by ThreatFabric earlier this February, is known to abuse Android’s accessibility permissions to conduct overlay attacks, wherein fake login screens are presented atop legitimate bank apps to steal victim’s credentials.

What’s more, the malware leverages a Telegram channel’s description to decode and construct the command-and-control (C2) domain used to receive additional commands.

The development follows the discovery of four rogue apps on Google Play that were found directing victims to malicious websites as part of an adware and information-stealing campaign. Google told The Hacker News that it has since banned the developer.





Source link

Related Articles

xxxanti beeztube.mobi hot sexy mp4 menyoujan hentaitgp.net jason voorhees hentai indian soft core chupatube.net youjzz ez2 may 8 2023 pinoycinema.org ahensya ng pamahalaan pakistani chut ki chudai pimpmovs.com www xvedio dost ke papa zztube.mobi 300mbfilms.in صور مص الزب arabporna.net نهر العطش لمن تشعر بالحرمان movierulz plz.in bustyporntube.info how to make rangoli video 穂高ゆうき simozo.net 四十路五十路 ロシアav javvideos.net 君島みお 無修正 افلام سكس في المطبخ annarivas.net فيلم سكس قديم rashmi hot videos porncorn.info audiosexstories b grade latest nesaporn.pro high school girls sex videos real life cam eroebony.info painfull porn exbii adult pics teacherporntrends.com nepali school sex