In late October, security researchers at Cleafy discovered a new Android banking trojan, dubbed SharkBot, targeting banks in Europe. The name comes from one of the domains used for the command and control servers.
See also: Alarming increase in banking trojans in recent months

The malware has been active since at least October 2021, targeting users of mobile apps from banks in Italy, the UK and the US. The trojan allows for the hacking of mobile devices and the theft of funds from online banking and cryptocurrency accounts.
Once the SharkBot banking Trojan infects the victim's device, its operators can steal important banking information (login credentials, personal information, current balance, etc.), through the abuse of Accessibility Services.
SharkBot uses overlay attacks to steal login credentials and credit card information.
Malware has multiple techniques to avoid detection and analysis.
See also: Mekotio trojan: It continues to spread despite the arrests of its operators
“SharkBot belongs to a ‘new’ generation of mobile malware, as it is able to perform ATS attacks inside the infected device. This technique has already been observed recently by other banking trojans, such as Gustuff,” the researchers report. “ ATS (Automatic Transfer System) is an advanced attack technique (quite new to Android) that allows attackers to automatically fill in fields in legitimate mobile banking applications and perform money transfers from the compromised devices to the attackers’ accounts.”

The Android banking trojan, SharkBot, abuses the Accessibility Service to perform ATS attacks inside the infected device. This technique allows for the automation of these actions, minimizing user intervention.
The Trojan can read and hide SMS, a feature that allows attackers to intercept 2FA codes sent by the bank via SMS.
See also: Joker malware makes a comeback! 7 apps have been infected
Experts did not find any samples of the malware in the official Google Play Store. They believe that the malicious code is delivered to users' devices through side-loading techniques and social engineering.
SharkBot can affect the applications of at least 22 banks.
“With the discovery of SharkBot, we show how mobile malware is quickly finding new ways to commit fraud, trying to bypass the protection measures that have been put in place by many banks and financial services in recent years,” the report concludes.
Source: Security Affairs
