HomeSecurityThousands of users fell victim to this Android Banking Botnet

Thousands of Users Fell Victims of This Android Banking Botnet

Botnet

A new Android Banking Botnet operating since at least 2016, discovered by researchers at the Czech Technical University, UNCUYO , and Avast, is targeting Russian citizens.

The Geost botnet, as it is called, has infected over 800,000 Android devices according to researchers' estimates, and the hackers behind it may have gained several million euros.

Researchers were able to discover the botnet when its creators decided to trust a malicious proxy network built using malware called HtBot. The malware provides a proxy service that can be rented to provide users with a pseudo-anonymous connection to the internet. By analyzing the communication of the HtBot network, the researchers discovered the large malicious enterprise.

Additionally, the hackers behind the botnet failed to encrypt their communications, which gave researchers unprecedented insight into their actions. The chat logs revealed how they accessed servers , introduced new devices to the botnet, and evaded detection by antivirus software

Thousands of Users Fell Victims of This Android Banking Botnet

A few words about the Geost botnet

According to Avast security researcher Anna Shirakova, the hackers' careless choices were what led to the discovery of their activities:

“We really have an unprecedented insight into how this type of operation works. Because this group made some very poor choices in how they chose to hide their actions, we were able to see not only samples of the malware, but also a deeper look into how the group operates, with lower-level operators bringing devices into the botnet, while those at the higher echelons handle whatever money they have under their control. In total, there were over eight hundred thousand victims, and the group potentially controls millions in digital currency as well.”

The Geost botnet appears to be a complex infrastructure of infected Android smartphones. The phones are initially infected with Android APKs that look like various fake applications, such as banking and social networking apps. Once an infected phone is connected to the botnet, it is remotely controlled and the attackers have access to the device and can proceed to send SMS messages, communicate with banks and redirect the data flow to different websites. They can also access a lot of the users' personal information.

The Geost botnet has a complex infrastructure consisting of at least 13 C&C IP addresses, over 140 domains, and more than 140 APK files. The banking Trojan were five banks, the majority of which were from Russia.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS