HomeYoutubeHook Android malware: Learn everything about the new big threat

Hook Android malware: Learn everything about the new big threat

Cybercriminals are now selling a new Android malware called “Hook,” which, when downloaded to your mobile device, has the ability to remotely take over it in real time via the VNC (virtual network computing) module.

The Hook malware is promoted by the creator of Ermac, an Android banking trojan that helps cybercriminals steal credentials from more than 467 banking and crypto apps.

Android malware hook

The creator of Ermac claims that the new Android malware Hook was written from scratch. However, researchers at ThreatFabric dispute these claims, arguing that while Hook has some extra features, it shares some of its code with the earlier Ermac.

See also: Predator inside story: SMS the key to the wiretapping investigation

ThreatFabric observed that Hook contains most of the Ermac codebase, so it is also a banking trojan.

Android malware Hook

Hook is an evolution of Ermac, offering an expanded set of features that make it a more dangerous threat to users with Android devices

A new feature of Hook compared to Ermac is the introduction of WebSocket communication added to HTTP traffic used exclusively by Ermac. The network traffic is encrypted using an AES-256-CBC hardcoded key.

However, the feature that stands out is “VNC.” Virtual Network Computing (VNC) is a specific implementation of a screen sharing app that provides remote control of the device. However, threat actors have begun to use this term to refer to any type of Remote Access Tool (RAT) feature. In the case of Hook, VNC provides malicious actors with interface user of a compromised device in real time.

This feature gives Hook operators the ability to do anything on the target device, such as extracting personal data or performing financial transactions.

“With this capability, Hook joins the class of malware families that can execute full DTO and complete a complete fraud, from PII extraction to transaction, with all intermediate steps, without the need for additional channels,” warns ThreatFabric.

See also: PayPal: Accounts compromised through credential stuffing attack

“This type of operation is much harder to detect by fraud detection engines.“.

However, it is worth noting that the Android malware Hook's VNC module requires access to the Accessibility Service to function, which may be difficult to obtain on devices running Android 11 or later.

Hook Android malware: Learn everything about the new big threat

According to researchers, Hook includes Ermac's commands, but is also equipped with new ones that allow it to perform the following actions:

  • Start/stop RAT
  • Performing a specific swipe gesture
  • Take a screenshot
  • Simulate a click on a specific text element
  • Key press simulation (HOME/BACK/RECENTS/LOCK/POWERDIALOG)
  • Unlocking device
  • Scroll up/down
  • and many more.

Additionally, there is a “ File Manager ” command that turns the malware into a file manager, giving perpetrators access to a complete list of all stored files and allowing them to download any documents they want.

ThreatFabric also uncovered another important command, which allows the Hook Android malware to record all messages on WhatsApp and enables attackers to send messages through the user's account.

Finally, there is a geolocation system that utilizes the “Access Fine Location” permission and allows Hook operators to know the exact location of the victim.

See also: MailChimp: New security breach of its employees

Targets of Hook malware

Hook's targeted banking apps affect users in the United States, Canada, Australia, Spain, Poland, Turkey, the United Kingdom, France, Italy, and Portugal.

ThreatFabric has listed all the applications targeted by Hook in report .

Currently, Hook is distributed as a Google Chrome APK with package names “com.lojibiwawajinu.guna”, “com.damariwonomiwi.docebi”, “com.damariwnomiwi.docebi” and “com.yecomevusaso.pisifo”, ​​but of course, this can change at any time.

Android malware is a common threat today and is commonly used to steal personal information, gain access to your bank accounts , or even take complete control of a device. By knowing what Android malware is and how it works, users can take steps, such as downloading apps only from trusted sources and regularly updating their operating system, to reduce the risk of infection.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS