HomeSecurityNew malware “Alien” steals passwords from 226 Android apps

New 'Alien' malware steals passwords from 226 Android apps

Security researchers have discovered and analyzed a new strain of Android malware that comes with a wide range of capabilities that allow it to steal credentials from 226 applications. Dubbed Alien, this new trojan has been active since the beginning of the year and is offered as Malware-as-a-Service (MaaS) on underground hacking forums.

In a report shared this week with ZDNet, security researchers at ThreatFabric pored over forum posts and Alien samples to understand the malware's evolution, tricks, and capabilities.

Alien Android

According to the researchers, Alien is not really a new piece of code, but was actually based on the source code of a rival malware called Cerberus.

Cerberus, while an active MaaS last year, collapsed this year, with its owner trying to sell the codebase and customerbase, before finally offering it for free on a hacking forum.

ThreatFabric says Cerberus died because Google's security team found a way to detect and clean infected devices. But even if Alien was based on an older version of Cerberus, it doesn't seem to have this problem.

And researchers say that Alien is even more advanced than Cerberus, which was a fairly reliable and dangerous trojan.

ThreatFabric reports that Alien is part of a new generation of Android banking trojans that have incorporated various remote access into their bases.

This makes Alien very dangerous. Not only can Alien display fake login screens and collect passwords for various applications and services, but it can also give access to devices to use those credentials or even perform other actions.

Currently, according to ThreatFabric, Alien has the following capabilities:

  • Ability to overlay content on top of other applications (feature used in phishing for credentials)
  • Enters a keyboard input
  • Provides remote access to a device after installing TeamViewer
  • Collects, sends or forwards SMS
  • It steals the contact list
  • Collects device details
  • Collects geolocation data
  • Makes USSD requests
  • Forward calls
  • Installs and launches applications
  • Launches browsers to desired pages
  • Locks the screen for a ransomware-type operation
  • Steals 2FA codes generated by authenticator apps

That's an impressive feature set. During their analysis, the researchers said they found that Alien had support for displaying fake login pages for 226 Android apps (you can see the full list in ThreatFabric's report).

Most of these fake login pages aim to steal credentials for e-banking apps, clearly supporting ThreatFabric's assessment that Alien was intended for this type of scam.

Most of the banking applications targeted were for financial institutions based primarily in Spain, Turkey, Germany, the US, Italy, France, Poland, Australia , and the UK.

ThreatFabric did not provide details on how Alien gets onto users' devices, mainly because this varies depending on how Alien MaaS customers chose to distribute it.

Some apps infected with malware are found on the Play Store, but most often they are distributed through other channels.

These malicious apps can be easily detected, as they often require users to grant them access to administrator privileges

Although it is an obvious piece of advice, we must mention it “do not install applications from strange websites and do not grant them administrator rights.” It may sound simple to some, but not all users have the ability or knowledge to realize that some applications are malicious.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS