The malicious actor behind an emerging Android banking trojan called SharkBot managed to bypass the security barriers of the Google Play Store after disguising itself as an antivirus application.

See also: Rompetrol gas station network hit by Hive ransomware
The SharkBot, like the related malicious programs TeaBot, FluBot and Oscorp (UBEL), belongs to a category of financial trojans capable of collecting credentials to initiate money transfers from compromised devices, bypassing multi-factor authentication mechanisms. This particular banking trojan first appeared in November 2021.
What distinguishes SharkBot is its ability to perform unauthorized transactions via Automatic Transfer Systems (ATS), which is in contrast to TeaBot, which requires a live operator to interact with infected devices to carry out malicious activities.
See also: Mozilla fixes two critical Firefox flaws
In other words, the ATS is used to deceive the fraud detection systems of the targeted bank by simulating the same sequence of actions that the user would perform, such as button presses, clicks and gestures, in order for the illegal transfer of funds to occur.
The latest version detected on the Google Play Store on February 28th is a series of dropper apps that leverage Android's Direct Reply feature to spread to other devices, making it the second banking trojan after FluBot to intercept notifications for wormable attacks.
The list of malicious applications (see the list below), which were all updated on February 10, have been installed a total of approximately 57,000 times to date:
- Antivirus, Super Cleaner (com.abbondioendrizzi.antivirus.supercleaner) – 1,000+ installations
- Atom Clean-Booster, Antivirus (com.abbondioendrizzi.tools.supercleaner) – 500+ installations
- Alpha Antivirus, Cleaner (com.pagnotto28.sellsourcecode.alpha) – 5,000+ installations
- Powerful Cleaner, Antivirus (com.pagnotto28.sellsourcecode.supercleaner) – 50,000+ installations

SharkBot is also feature-rich, allowing the adversary to insert fraudulent overlays into official banking applications to steal credentials, record keystrokes, and gain full remote control of devices, but only after its victims grant permissions to Accessibility Services.
See also: Access:7 vulnerabilities affect medical and IoT devices
The findings come a week after researchers at Cleafy revealed details of a new TeaBot variant found on the Play Store that is designed to target users of more than 400 banking and financial apps, including those from Russia, China, and the US.
Information source: thehackernews.com
