Cybersecurity researchers analyze MaliBot, a powerful new Android malware!
A new form of Android malware recently discovered steals passwords, banking information, and cryptocurrency wallets from users – and it does so by bypassing multi-factor authentication protections.
See also: SMSFactory Android malware: How does it “inflate” your account?

The malware was analyzed by cybersecurity researchers at F5 Labs, who dubbed it MaliBot. It is the latest in a series of powerful malware targeting Android users.
In addition to remotely stealing passwords, banking details , and cryptocurrency wallets, MaliBot can access messages, steal browser cookies , and take screenshots from infected Android devices. It can also bypass multi-factor authentication (MFA) checks – one of the key defenses people can use to protect themselves from cybercriminals .
See also: FluBot Android malware: Authorities shut it down
Like many Android malware threats, MaliBot is distributed by sending phishing messages to users' phones via SMS text messages (smishing) or by luring victims to fraudulent websites. In both cases, victims are encouraged to click on a link, which downloads malware to their phone.
So far, researchers have found two malicious websites used to distribute MaliBot – one is a fake version of a legitimate cryptocurrency tracker app with more than a million downloads from the Google Play Store.
Once downloaded, MaliBot asks the victim to grant it accessibility and launch permissions required to monitor the device and perform malicious operations. This includes stealing sensitive information, such as passwords and banking details.
Google Android users are encouraged to use two-step verification, designed to protect accounts from being accessed by intruders, even if the password is known – but the cybercriminals behind MaliBot know this and have devised a way to get around it.
Once MaliBot captures the credentials on the device, it can bypass multi-factor authentication by using accessibility permissionsto click the "Yes" button on the prompt asking if the user is trying to log in.
MaliBot also uses a similar technique to bypass additional protections around cryptocurrency wallets, allowing attackers to steal any Bitcoin or other cryptocurrencies from accounts linked to the infected Android smartphone.
In addition to stealing sensitive information and currency from the victim, MaliBot is also equipped with the ability to send SMS messages that can be used to infect others with the malware – a tactic similar to the one that allowed the FluBot malware to become so successful.

Currently, the MaliBot campaign exclusively targets customers of Spanish and Italian banks, but the researchers warn that "we can expect a wider range of targets to be added to the application as time goes on."
MaliBot's powerful capabilities that allow control of an infected device could "be used for a wider range of attacks than stealing credentials and cryptocurrency."
See also: Android banking malware remotely takes control of devices
To avoid falling victim to MaliBot attacks or other Android malware, users should be cautious about downloading apps from third-party websites and not click on links they don't know where they came from.
Information source: zdnet.com
