HomeSecurityMMRat: Learn everything about the new Android banking malware

MMRat: Learn everything about the new Android banking malware

A new Android banking malware, dubbed MMRat, uses a rare communication method, known as protobuf data serialization, to more efficiently steal data from devices.

MMRat malware

MMRat was first detected by Trend Micro in June 2023. Its main targets are users in Southeast Asia. The malware managed to remain hidden for some time, as it cannot be detected by virus scanning services such as VirusTotal.

Researchers discovered that MMRat is distributed through websites that present themselves as official app stores.

Victims download and install malicious apps carrying the MMRat banking malware through these app stores. The apps typicallymimic an official government app or a dating app. However, upon installation, they request dangerous permissions, such as access to Android's Accessibility service.

The malware automatically abuses the Accessibility feature to gain additional permissions that will allow it to perform a range of malicious activities on the device.

See also: Android malware CherryBlos steals passwords using OCR

MMRat Android banking malware: Features

Once the MMRat malware infects an Android device, it establishes a communication channel with the C2 server and monitors the device to detect periods of inactivity.

During these periods, banking malware operators abuse the Accessibility Service to remotely open the device, unlock the screen, and commit banking fraud in real time.

MMRat's main functions:

  • Stealing the user's contact list and list of installed applications
  • Collecting network, screen, and battery information
  • Keylogging
  • Real-time screen content capture by abusing the MediaProjection API
  • Recording and live-streaming camera
  • Sending data to the C2 server
  • Uninstall from the device and delete all evidence of infection

MMRat's ability to capture screen in real time, and even the most rudimentary “user terminal state” method that extracts text data that requires reconstruction, require efficient data transmission.

Without it, the operators of the MMRat Android banking malware would not be able to effectively execute banking fraud, so they chose to develop a custom Protobuf protocol for data extraction.

See also: Hackers rent WikiLoader to attack Italian organizations with banking trojan

Android banking malware

Protobuf Advantage

MMRat uses a unique command and control (C2) server protocol that relies on protocol buffers (Protobuf) for efficient data, something we don't often see in Android trojans.

Protobuf is a method of serializing structured data developed by Google.

MMRat uses different ports and protocols to exchange data with the C2, such as HTTP on port 8080 for data extraction, RTSP and port 8554 for video streaming, and custom Protobuf on 8887 for command and control.

“The C&C protocol, in particular, is unique due to its customization based on Netty (a network application framework) and the aforementioned Protobuf, complete with well-designed message structures,” Trend Micro reports.

“For C&C communication, the attacker uses a generic structure to represent all message and the keyword “oneof” to represent different data types.”.

See also: QakBot, SocGholish and Raspberry Robin: The most popular malware loaders of 2023

In addition to the effectiveness of Protobuf, custom protocols also help threat actors avoid detection by network security tools.

Protobuf's flexibility allows the authors of the MMRat banking malware to define their message structures and organize how data.

The way MMRat operates shows the sophistication of the new Android banking trojans. Android users should be even more careful and only download apps from the official app store, Google Play. Even then, they should check other users' reviews, trust only reputable publishers , and check the permissions that apps during installation. If they ask for permission to access sensitive data that is not needed for the app to function, avoid downloading them. Android devices should also be regularly updated to receive security updates, and it is a good idea to use antivirus software.

Android banking malware, such as MMRat, poses a significant threat to users. The theft of personal and banking information can create serious problems.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS