HomeSecurityMonokle: Mobile Trojan targets VIPs of Android and iOS devices!

Monokle: Mobile Trojan targets VIPs on Android and iOS devices!

Monokle: Security researchers have uncovered a new Mobile Trojan believed to have been developed by a Russian company accused of interfering in the 2016 US presidential election.

We're talking about Monokle, a mobile remote-access trojan that has been actively targeting Android phones since March 2016 andis primarily used in highly targeted attacks on a limited number of people.

Monokle Mobile trojan

According to security researchers, Monokle has a wide range of spying functions and uses advanced data theft techniques, even without requiring root access on the target device.

How dangerous is Monokle?

The malware abuses Android's accessibility services to steal data from popular third-party apps, including Google Docs, Facebook messenger, Whatsapp, WeChat, and Snapchat, by reading the text displayed on the device's screen.

The malware also attempts to capture the phone's screen during a screen unlock in order to steal the PIN, pattern, or password.

Additionally, if root access is available, the spyware installs root CA certificates specified by the attacker into the trusted certificate list of the compromised device, thus allowing attackers to easily bypass encrypted SSL-protected network traffic via Man-in-the-Middle (MiTM) attacks.

Monokle Mobile trojan

Features of Monokle:

  1. Device location tracking
  2. Audio and call recording
  3. Screen recording
  4. Keylogger and fingerprint capture
  5. Retrieval of browsing and call history
  6. Capture of photos, videos and screenshots
  7. Retrieval of email messages and SMS messages
  8. Stealing contacts and calendar information
  9. Making calls and sending text messages on behalf of victims
  10. Execution of arbitrary shell commands as root, if root access is available

In total, Monokle contains 78 different predefined commands, which hackers can send via SMS, phone calls, emails via POP3 and SMTP, and incoming/outgoing TCP connections, instructing the malware to extract the requested data and send it to the C&C servers.

The Spyware masquerades as PornHub and Google Apps for Android

According to researchers, attackers are distributing Monokle through fake apps that look like Evernote, Google Play, Pornhub, Signal, UC Browser, Skype, and other popular Android apps.

Most of these apps even include legitimate functionality, preventing victims from suspecting that the apps are malicious.

Additionally, some recent Monokle samples feature Xpose modules that allow the malware to customize some system functions, potentially extending its ability to hide its presence in the process directory.

Monokle

The malware package uses a DEX file in its assets folder , which includes all the cryptographic functions used in the open source library “spongycastle”, various email protocols, extraction of all data, and encoding among many other functions.

The Android malware and its capabilities remind us of the powerful Pegasus malware, which was developed by the Israeli NSO Group for Apple iOS and Google Android devices.

Creator of Monokle

Monokle was developed by a Russiancalled Special Technology Center Ltd. (STC) – known for producing UAVs and radio frequency (RF) equipment for the Russian military as well as other government clients.

Mobile trojan

Monokle for iOS under development

In addition to Android, researchers have also identified several samples of Monokle malware, analysis of which revealed the existence of iOS versions of Monokle targeting Apple, although researchers have not found any evidence of iOS infection as of yet.

Some commands in the malware samples appear to serve no purpose in the Android client and were likely added unintentionally, suggesting that iOS of Monokle may be in development.

These commands include iOS functions for keychain, iCloud logins, iWatch accelerometer data, iOS permissions, and iOS services.

According to Lookout researchers, Monokle is being used in highly targeted attacks on a limited number of individuals in regions of Eastern Europe, as well as individuals interested in Islam and the militant group Ahrar al-Sham in Syria , and individuals in Central Asia and the former Soviet republic of Uzbekistan.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS