A new darknet platform called “Zombinder” allows cybercriminals to attach malware to legitimate (Android) apps. As a result, victims are infected while the app retains its original features and functionality, allowing malicious activity to go unnoticed.
This new platform was discovered by cybersecurity ThreatFabric, which identified malicious campaigns distributing malware to Windows and Android devices.

The campaign impersonates Wi-Fi authorization portals to supposedly help users access internet hotspots. The website then asks the user to download a Windows or Android version of the app, which is actually malware.
See also: Agrius team uses Fantasy data wiper in supply chain attacks
ThreatFabric says in its report that the malicious campaign has already claimed thousands of victims, with infections by the Erbium stealer malware having led to data theft from 1,300 different computers.
Zombinder for Android
An interesting aspect of the campaign is the darknet service, which the researchers have dubbed “Zombinder.” This service helps embed malware into legitimate Android apps.
The Zombinder service was launched in March 2022 as a malware packer in APK files according to ThreatFabric. It has now become very popular in the cybercrime community.
In this campaign, the APKs vary - analysts have seen a fake football streaming app and a modified version of the Instagram.
These applications work as expected because the functionality of the legitimate software is not affected or removed. The Zombinder service adds a malware loader to the code.

The loader is designed to evade detection. So, when the user opens the application, the loader will display a request to install a plugin. If accepted, the loader will install the malware and activate it without the user.
The Zombinder service provider claims that malicious app packages created with it cannot be detected at runtime and can bypass Google Protect or AV alerts running on target devices.
See also: How does the new Zerobot malware work?
Android apps are infected with the Ermac payload , which can record keystrokes (keylogging), perform overlay attacks, and steal Gmail emails , 2FA passwords, and seed phrases for crypto wallets
Zombinder: Windows malware
As mentioned above, the campaign impersonates Wi-Fi authorization portals . If the visitor to the Wi-Fi authorization website clicks the “ Download for Windows ” button, they download malware for Windows.
Some of the malware seen by ThreatFabric include the Erbium stealer, the Laplas clipper, and the Aurora info-stealer.
These are dangerous malware that are under active development, which are rented to cybercriminals.

ThreatFabric says that the wide variety of trojans delivered from the same malicious pages may indicate that a single third-party malware distribution service serves multiple threat actors.
See also: Why are the holidays the best time for scammers?
The modern threat landscape is becoming increasingly complex, with attackers combining multiple approaches to developing, distributing, and operating malware. New tools are hindering detection, leading to more successful attacks. Additionally, by targeting multiple platforms, actors can reach a wider “audience” and steal more data to use in further fraud.
Malware infections have become increasingly common in recent years, but there are steps you can take to protect yourself from these threats. Keeping systems and applications updated, installing antivirus software, and backing up data are key components of an effective malware protection strategy.
More details about the new Android and Windows malware distribution campaign via the Zombinder service can be found in the ThreatFabric report
Source: www.bleepingcomputer.com
