A new Android malware strain called BlackRock has emerged in the criminal underworld and comes equipped with a broad range of data theft capabilities that allow it to target 337 Android applications.
This new threat appeared in May of the current year and was discovered by the mobile security company ThreatFabric.

Researchers say that the malware was based on the source code leak of another malware strain (Xerxes, based on other malicious software strains), but it was enhanced with additional capabilities, especially on the side dealing with stealing user passwords and credit card information.
BlackRock still operates like most Android banking trojans, except that it targets more apps than most of its predecessors.

The trojan will steal the login credentials (username and password), where they are available, but will also ask the victim to enter payment card details if the apps support financial transactions.
For ThreatFabric, data collection is carried out through a technique called “overlays,” which is implemented when the user tries to interact with a legitimate application and displays a fake window on top that collects the victim’s login and card data before allowing the user to enter them into the intended legitimate application.
In a report released this week, researchers at ThreatFabric say the vast majority of BlackRock overlays are targeted at financial and social media. However, overlays targeting data phishing from dating, news, shopping, lifestyle, and productivity apps are also included.

Aside from the overlays, BlackRock is not that unique as it operates like most Android malware these days and uses old and proven techniques.
Once installed on a device, a malicious application infected with the BlackRock trojan asks the user to grant it access to the accessibility .
The Android Accessibility feature is one of the most powerful capabilities of the operating system, as it can be used to automate tasks and even perform “click” on behalf of the user.
BlackRock uses Android Accessibility to access other permissions , and then uses an Android DPC (device policy controller, also known as a work profile) to give itself administrator access to the device.
It then uses this access to display the malicious overlays, but ThreatFabric says the trojan can also execute other annoying functions, such as:
- Monitoring SMS messages
- Unsolicited contacts with predefined SMS
- Launch specific applications
- Keylogger operation
- Show custom push notifications
- Sabotage antivirus apps
Currently, BlackRock is distributed disguised as a fake Google update package offered on third‑party websites and has not yet been detected in the official Play Store.
However, Android malware gangs have found ways to bypass Google's app review process, and at some point, we'll likely see BlackRock launch on the Play Store.
