HomeSecurityAndroid malware BrazKing returns as banking trojan

Android malware BrazKing returns as a banking trojan

The BrazKing banking trojan that affects Android operating systems has returned with new features and an implementation trick that allows it to operate without asking for permission.

BrazKing

See also: Alarming increase in banking trojans in recent months

A new malware sample was analyzed by IBM Trusteer, on websites where people end up after receiving smishing (SMS) messages.

These HTTPS sites warn their potential victim that they are using an outdated Android version and offer an APK that is said to update them to the latest version.

If the user approves “downloads from unknown sources”, the malware enters the device and requests access to the “Accessibility Service”.

This permission is abused to capture screenshots and keystrokes without requesting additional permissions that could raise suspicion.

Specifically, the Accessibility Service is used by BrazKing for malicious activity such as:

  • Screen dissection via programming instead of screenshots. This can be done via programming, but on a device without root, it would require explicit user consent.
  • Keylogger capabilities by reading screen shots.
  • RAT capabilities, which allow controlling the targeted banking application by pressing buttons or typing text.
  • Reading SMS without the "android.permission.READ_SMS" permission. This can give malicious actors access to 2FA codes.
  • Access to contact lists, without the "android.permission.READ_CONTACTS" permission by reading contacts in the "Contacts" application.

See also: The Android app “Smart TV remote” on Google Play is malware

Starting with Android 11, Google has classified the list of installed apps as sensitive information, so any malicious software that attempts to retrieve it is flagged by Play Protect as malicious.

banking trojan

BrazKing, however, no longer uses the "getinstalledpackages" API request like it used to, but instead uses the screen dissection feature to see which applications are installed on the infected device.

It loads the fake screen as a URL from the attacker’s server into a web view window added by the accessibility service. This covers the app and all its windows, but does not force exiting it.

When detecting a connection to an online bank, instead of displaying embedded overlays, the malware will now connect to the command and control server to obtain the correct connection overlay.

This dynamic overlay system facilitates threat actors stealing credentials for a broader range of banks. It also allows them to update login screens as required, so they match changes in legitimate banking apps or websites or add support for new banks.

If the user attempts to delete the malware, move to the "Back" or "Home" buttons to prevent the action.

The same trick is used when the user tries to open an antivirus protection app, hoping to scan and remove the malware.

See also: Android malware MasterFred: Targets Netflix, Instagram & Twitter users

The evolution of BrazKing shows that malware creators adapt quickly to provide more covert versions of their tools, as Android security strengthens.

The ability to steal 2FA codes, credentials, and capture screen screenshots without storage permissions makes the trojan much more powerful than it was before, so be very careful with APK downloads outside the Play Store.

According to the report , BrazKing appears to be operated by local hacking groups, as it is circulating on Portuguese-speaking websites.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS