An advanced malware program originating from Brazil has begun targeting Android users to steal banking credentials. The banking trojan dubbed Bizarro, targets customers of 70 banks in Europe and South America.
See also: Janeleiro: The new banking trojan that targets organizations and governments

According to a Kaspersky released on Monday, Bizarro is a mobile malware that aims to steal online-banking credentials and compromise Bitcoin wallets of Android users. It spreads via Microsoft Installer packages, which can be downloaded directly by victims from links in spam emails or installed via a trojanized application.
Once installed, the Bizarro malware interrupts all running browser processes to terminate any existing sessions with banking sites. Therefore, when a user starts a mobile banking session, they must log in again, allowing the malware to steal credentials. To increase its chances of success, the Bizarro banking trojan disables autocomplete in the browser and even displays fake pop-ups to grab two-factor authentication passwords.
See also: Teabot: New Android malware targets banks in Europe!
Bizarro also has the ability to record the screen of an Android device.
“It loads the magnification.dll library and gets the address of the deprecated MagSetImageScalingCallback API function,” Kaspersky researchers explained. “With its help, the Bizarro trojan can record a user’s screen and also constantly monitor the system clipboard, searching for the address of a Bitcoin wallet. If it finds a wallet, it replaces it with another one belonging to the malware developers.”
Finally, according to the analysis, the Bizarro trojan also has a backdoor module that is capable of executing more than 100 commands.
The commands are divided into the following categories:
- Commands that allow C2 operators to obtain data about the victim and manage connection status.
- Commands that allow attackers to search for and steal files located on the victim's hard drive and commands that allow files to be installed on the victim's device.
- Commands that allow attackers to control the user's mouse and keyboard.
- Commands that allow attackers to control the operation of the backdoor, shut down, restart, or crash the operating system, and limit Windows functionality.
- Commands that record keystrokes.
- Commands that enable social engineering attacks: These commands display various messages that mislead users into giving attackers access to bank accounts, including fake pop-up windows (e.g. messages like “the data entered is incorrect, please try again”, error messages asking the user to enter a confirmation code, messages telling the user that their computer must be restarted to complete a security-related operation, etc.).
- Commands that allow the Bizarro banking trojan to mimic online banking systems.
- Commands that trigger custom messages.
“The custom messages that Bizarro can display are messages that freeze the victim’s machine, thus allowing attackers to buy some time,” the analysis says. “When a command to display such a message is received, the taskbar is hidden, the screen is grayed out, and the message itself is displayed. While the message is displayed, the user cannot close it or open Task Manager. The message itself tells the user either that the system has been compromised and therefore needs to be updated, or that security components are being installed.”
See also: Avast: Ursnif Trojan has targeted over 100 banks in Italy

According to researchers, the Bizarro banking trojan has targeted users in Argentina, Chile, Germany, France, Spain, Portugal, and Italy. Bizarro is not the first banking trojan to originate from Brazil and start targeting users around the world. Other well-known trojans have operated in the same manner: Grandoreiro, Guildma, Javali, and Melcoz.
“Cybercriminals are constantly looking for new ways to spread malware that allows the theft of credentials for online payment systems and banking systems,” said Fabio Assolini, security expert at Kaspersky. “Today, we are seeing a game-changing trend in malware distribution – attackers who previously targeted users only in their region are now targeting users all over the world. Applying new techniques, Brazilian malware has started targeting users on other continents, and Bizarro, which targets users from Europe, is the most prominent example.”
Source: Threatpost
