HomeSecurityAndroid malware Revive appears as a Spanish bank's 2FA app

Android malware Revive appears as Spanish bank's 2FA app

A new Android banking malware, dubbed Revive, is posing as a 2FA app for logging into BBVA bank accounts in Spain. This new trojan appears to be more focused, targeting BBVA bank. In contrast, other similar malware attempts to target customers of many financial institutions.

Revive Android malware

According to the researchers at Cleafy, who discovered Revive, the malware is in an early stage of development. However, it is already capable of doing many things, such as tracking two-factor authentication (2FA) codes and “one-time” passwords.

See also: Emails warn of copyright infringement and install LockBit ransomware

Revive mimics a 2FA application

According to Cleafy analysts, the new malware targets potential victims through phishing attacks, convincing them to download an app that is supposed to be a 2FA tool, which offers more security to accounts their.

The phishing messages that victims receive claim that the 2FA feature built into the real bank's app no ​​longer meets security level requirements, so users must install this additional tool to protect their accounts.

The app is hosted on a site that looks official and authentic, and even has an instructional video to guide victims through the process of downloading and installing the 2FA app.

See also: Phishing method bypasses MFA via Microsoft WebView2 apps

During installation, Revive asks for permission to use the Accessibility Service, which essentially gives it full control of the screen.

2FA malware

When the user opens the app for the first time, they are asked to grant it access to SMS and phone calls, which doesn't seem too strange, given that we are talking about a 2FA program (so it can access one -time codes sent via messages).

The Revive malware runs in the background as a simple keylogger, recording everything the user types on the device and sending it to the C2. Therefore, credentials are also sent to the threat actors' C2, and then a generic homepage is loaded with links to the real website of the targeted bank.

Based on the analyses conducted by Cleafy researchers, it appears that the creators of the Revive malware were inspired by Teardroid, an Android spyware whose code is publicly available on GitHub.

The two malware exhibit similarities in the API, in the web framework, and in some functionalities.

See also: US: Senators ask FTC to investigate Google and Apple's data practices

According to the researchers, Revive malware is not easily detected by security vendors. Most likely, the focus on specific targets, small campaigns, and localized operations do not give security much opportunity to capture these threats and define detection parameters.

At this time, it is unclear how Revive will evolve, as the malware is still in its early stages, as we mentioned above. Its operators could add even more features or start targeting users of different banks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS