A new version of the Xenomorph Android malware has been released with increased malicious capabilities, such as the Automatic Transfer System framework and the ability to steal credentials from 400 banks. Now equipped with these powerful tools, it can carry out even more harmful attacks on unsuspecting victims.
Xenomorph was first identified by ThreatFabric in February 2022, which discovered the first version of the banking trojan on the Google Play store, where it amassed over 50,000 downloads.
To launch the first version of their attack, the criminals targeted 56 European banks with overlay attacks and Accessibility Services permissions. This allowed them to steal one-time codes sent via notifications.
The development of the malicious software continued throughout 2022 by its creators, “Hadoken Security”, but its newer versions were never distributed in large volumes.
Conversely, Xenomorph v2, which was released in June 2022, had only brief bursts of testing activity. However, the second version was notable for the complete code overhaul, which made it more flexible.
Xenomorph v3 is far more capable than previous versions, capable of automatically stealing data, including credentials, remaining account balances, executing bank transactions, and finalizing capital transfers.
According to ThreatFabric, Hadoken is planning the distribution of Xenomorph via a MaaS (malware as a service) platform. The recently created website promoting the latest version of this malicious software further strengthens this hypothesis.

Currently, Xenomorph v3 is being distributed via the platform under the deceptive name “Zombinder” on the Google Play store. Once installed, the malicious payload installs a currency converter and adopts the Google Play Protect icon for additional deception.

Who does the new Xenomorph target?
The recent release of Xenomorph focuses on 400 financial institutions worldwide, in countries such as the United States, Spain, Turkey, Poland, Australia, Canada, Italy, Portugal ,France, Germany, the United Arab Emirates , and India.
Some examples of targeted institutions include Chase, Citibank, American Express, ING, HSBC, Deutsche Bank, Wells Fargo, Amex, Citi, BNP, UniCredit, National Bank of Canada, BBVA, Santander and Caixa.
Additionally, this malicious code has the ability to attack 13 different cryptocurrency wallets, including Binance, BitPay, KuCoin, Gemini, and Coinbase.
Automatic MFA bypass
The latest version of Xenomorph introduces a powerful ATS framework, which allows hackers to quickly and easily extract credentials, check account balances, perform transactions , and steal funds from target applications – all without taking any remote actions.
Conversely, the operator simply sends JSON scripts which Xenomorph converts into a list of functions and executes them autonomously on the infected device.
One of the most impressive capabilities of the malware's ATS framework is its ability to capture the content of third-party authentication applications, bypassing MFA (multi-factor authentication) protections that would otherwise prevent automated transactions.

As banks move increasingly away from SMS MFA to authentication apps, Xenomorph's ability to access these apps on the same device is concerning.

Cookies stealer
Additionally, the updated Xenomorph includes a cookie stealer that can steal cookies from the Android CookieManager – which holds users' session cookies.
The stealer launches a browser window that displays an authentic service with a JavaScript-enabled interface, tricking the victim into entering login details .
By stealing cookies, malicious actors are able to take control of victims' web sessions and ultimately infiltrate their accounts.

An Android malware you should be concerned about
A year ago, Xenomorph appeared as a pioneering malicious software that threatened the cybercrime community.
Recently, the third major version of this malicious software was released and now represents an even greater risk for Android users worldwide.
If you're downloading apps from Google Play, it's important to be cautious with Zombinder: read reviews and research the publisher before hitting the install button. This way, you can ensure that your security remains intact throughout the process.
It is highly recommended to install and keep only a minimal number of apps on your phone, preferably those that come from trusted sources.
Information source: bleepingcomputer.com
