HomeinetAcecard Trojan: Users of 30 banking and payment system applications at risk...

Acecard Trojan: Users of 30 banking and payment system apps for Android at risk

Acecard Trojan: Kaspersky Lab's anti -malware research team has identified one of the most dangerous banking Trojans for Android devices ever. The Acecard malware has the ability to attack users of around 30 online financial apps and services and can bypass the security measures of the Google Play store.Acecard Trojan

During the third quarter of 2015, Kaspersky Lab experts detected an unusual increase in the number of mobile banking attacks in Australia. This increase seemed suspicious, and it was soon revealed that the main reason for its appearance was a single banking Trojan: Acecard.

The Acecard Trojan family uses almost all available malware features: from stealing a bank’s text and voice messages, to overlaying official application windows with fake messages that resemble an official login page, in an attempt to steal personal information and account details. The latest versions of the Acecard family can attack client applications from about 30 banks and payment systems. Considering that these Trojans have the ability to overlay any application on command, the total number of financial applications that have been attacked may be much higher.

In addition to banking applications, Acecard can also overlay the following applications with phishing windows:

  • Instant messaging services: WhatsApp, Viber, Instagram, Skype
  • Social Media: VKontakte, Odnoklassniki, Facebook, Twitter
  • Gmail
  • The PayPal mobile app
  • The Google Play and Google Music apps

This malware was first detected in February 2014, but for a long time it showed almost no malicious activity. Everything changed in 2015, when Kaspersky Lab researchers detected a sharp increase in attacks: from May to December 2015, more than 6,000 users were attacked by this Trojan. Most of them were targeted at people living in Russia, Australia, Germany, Austria and France.

During the two-year observation, Kaspersky Lab researchers witnessed the active development of the Trojan. They recorded more than 10 new versions of the malware, each of which had a much longer list of malicious functions than the previous one.

Mobile devices were typically infected after downloading a malicious application that was presented as legitimate. Acecard versions are usually distributed as Flash Player videos or porn, although other names are sometimes used in an attempt to imitate popular software.

But this is not the only way this malware is distributed. On December 28, 2015, Kaspersky Lab experts detected a version of the Acecard downloader Trojan (Trojan-Downloader.Android OS.Acecard.b) in the official Google Play store. To distribute it, the Trojan “hides” behind a game. When the malware is installed from Google Play, the user will only see an Adobe Flash Player icon on their desktop and no real indication of the installed application.Acecard Trojan

By carefully examining the malware's code, Kaspersky Lab experts tend to believe that Acecard was created by the same group of cybercriminals that was responsible for the first TOR Trojan for Android devices (Backdoor.AndroidOS.Torec.a) and the first mobile encryptor/ransomware (Trojan-Ransom.AndroidOS.Plethor.a).

The evidence for this is based on similar lines of code (method and class names) and the use of the same C&C (Command and Control) servers. This fact proves that Acecard was created by a strong and experienced group of criminals, most likely Russian-speaking.

“This group of cybercriminals uses almost every available method to spread the Acecard banking Trojan. It can be distributed under the guise of another program, through official app stores, or via other Trojans. A distinctive feature of this malware is that it is capable of overlaying more than 30 banking and payment systems, as well as social media, instant messaging, and other applications. The combination of Acecard’s capabilities and distribution methods make this malware one of the most dangerous threats to users today,” warns Roman Unuchek, Senior Malware Analyst at Kaspersky Lab in the US.

To avoid being "infected" by this malware, Kaspersky Lab recommends the following:

– Do not download and/or install any applications from Google Play or internal sources, if they are not trustworthy or cannot be considered as such

– Do not visit suspicious websites with specific content and do not click suspicious links

– Install a reliable mobile security solution, such as Kaspersky Internet Security for Android

– Make sure your antivirus databases are up to date and working properly

More information about the Acecard Trojan is available in a dedicated blogpost on the Securelist.com.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS