HomeSecurity"Escobar" banking trojan steals Google Authenticator MFA codes

“Escobar” banking trojan steals Google Authenticator MFA codes

The Aberebot Android banking trojan appears to have returned under the name "Escobar" and with new features, which include the ability to steal Google Authenticator MFA codes.

Furthermore, the new version of Aberebot, Escobar, allows controlling infected Android devices using VNC, recording audio, taking photos, etc.

See also: Banking malware: The most dangerous trojans that have ever existed!

Escobar banking trojan

The banking trojan's main goal is to steal enough information that will allow its operators to take control of victims' bank accounts, steal available balances, and make unauthorized transactions.

Aberebot Android banking trojan renamed to Escobar

According to BleepingComputer, there was a post on a Russian-language hacking forum from February 2022. In this post, the developer of Aberebot promotes his new version under the name “Escobar Bot Android Banking Trojan”.

The malware creator is renting out the beta version of the malware for $3,000 per month to five customers (maximum number). Threat actors are given the option to try the bot for free for three days.

The developer of the Escobar banking trojan plans to increase the price of the malware to $5,000 after development is complete.

MalwareHunterTeam first detected the suspicious APK on March 3, 2022, disguised as a McAfee app and warned about its enhanced capabilities to avoid detection.

However, Cyble researchers managed to analyze the “Escobar” variant of the Aberebot trojan. According to the same analysts, Aberebot first appeared in the summer of 2021. The appearance of the new version suggests that its operators are constantly developing it.

Old and new features of the Android trojan

As with most banking trojans, Escobar displays overlay login forms to hijack users' interactions with e-banking applications and sites and steal credentials from victims.

However, the malware also comes with new features that make it even more powerful.

It is also said that the creators have expanded the set of targeted banks and financial institutions to 190 entities from 18 countries.

See also: Explosion in mobile malware attacks – what to watch out for

The malware requests 25 permissions, 15 of which are used for malicious purposes. Some of the permissions are related to accessibility, audio recording, reading SMS, making calls, storing/writing, getting account list, disabling lock, and accessing the device's precise location.

All data collected by the malware is uploaded to the C2 server (e.g. key logs, notifications, and Google Authenticator MFA codes) which is controlled by attackers.

The above allows attackers to overcome two-factor authentication barriers when taking control of e-banking accounts.

2FA codes arrive via SMS or using apps like Google Authenticator. The latter is considered more secure because it is not vulnerable to SIM swap attacks, but that doesn't mean there aren't other risks.

Additionally, the use of VNC Viewer, a screen sharing program with remote control capabilities, gives attackers a powerful new weapon to do whatever they want when the device is unprotected.

In addition to the above, the new version of Aberebot, Escobar, can also record audio clips or take screenshots and transfer them to the C2 server controlled by the criminals. The supported commands are available in the table below:

"Escobar" banking trojan steals Google Authenticator MFA codes

See also: Malware targets supporters and members of Ukraine's IT Army

Is the risk great?

We don't know yet how popular the new Escobar banking trojan is in the cybercrime community, but it is certainly powerful enough to attract many criminals.

You can minimize your chances of getting infected by the Android trojan by avoiding installing APKs outside of Google Play, using a mobile security tool, and ensuring that Google Play Protect is enabled on your device. Additionally, when installing a new app, pay attention to the permissions it requests and check for suspicious elements, such as any changes (e.g. faster battery drain, etc.) that could indicate something is wrong.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS