The Android malware called BRATA has added some new features to its latest version, such as GPS tracking, the ability to use multiple communication channels, and a function that performs a factory reset to erase all traces of malicious activity from the device.
The BRATA Android malware was first detected by Kaspersky in 2019. The cybersecurity company described BRATA as an Android RAT (remote access tool) that primarily targeted Brazilian users.
See also: Canada's Foreign Ministry victim of cyberattack

In December 2021, Cleafy researchers also detected the malware in Europe. The malware targeted usersbanking and stole their credentials with the help of scammers posing as bank customer support.
Cleafy analysts continued to monitor the evolution of the BRATA Android malware and published a report showing how the malware continues to evolve and acquire new features and functions.
Customized versions for different goals
The latest versions of the BRATA Android malware target e-banking users in the UK, Italy, Spain, Poland, China, and Latin America.
A major upgrade is that each variant of the malware focuses on different banks with dedicated overlay sets, languages, and even different applications to target specific individuals.
See also: PowerPoint files used to distribute RATs and info-stealers
The creators use similar obfuscation across all versions, such as wrapping the APK file in an encrypted JAR or DEX package.
According to researchers, obfuscation techniques successfully bypass antivirus solutions.
BRATA actively searches for signs of AV presence on the device and attempts to delete security tools before proceeding to steal data.

BRATA Android malware: New features and functions
The new features identified by Cleafy researchers in the latest BRATA versions include, among others, the “keystroke” recording function that complements the existing screenshot capture function for screen monitoring.
As we said above, the new variants also feature GPS tracking.
However, one of the most dangerous possibilities is performing a factory reset, which is done in the following cases:
- The breach was successfully completed and the credentials were stolen.
- The application has detected that it is running in a virtual environment, likely for analysis.
BRATA performs a factory reset as a “kill switch” for self-protection. If the malware “realizes” that it can be detected, it performs the reset to erase traces of malicious activity. However, this likely means that the user’s data will also be deleted.
See also: Cryptocurrency token rug pulls: Hackers hijack smart contracts
Finally, the researchers observed that BRATA added new communication channels for exchanging data with the C2 server and now supports HTTP and WebSockets.
WebSockets gives actors a direct and low-latency channel that is ideal for real-time communication and live manual exploitation.

How to stay safe?
BRATA Android malware joins the list of Android banking trojans and RATs that target users' banking credentials.
To protect your Android device from malware, you need to be very careful about the apps you download. Choose apps from the Google Play Store, avoid APKs from strange sites , and scan them with an AV tool before opening them.
Also, before proceeding with the installation, check the permissions an application requests and if you see that it requests excessive permissions for its operation, avoid it.
Finally, monitor battery consumption and network traffic volume to identify possible strange elements, which may be attributed to malicious processes running in the background.
Source: Bleeping Computer
