Researchers have discovered a new Xenomorph malware, targeting Android users in the US, Canada, Spain, Italy, Portugal, and Belgium.

Analysts at cybersecurity firm ThreatFabric have been monitoring Xenomorph activity since February 2022. The new campaign, however, began in August of this year.
The latest version of Xenomorph targets users with crypto wallets and customers of various financial institutions in the US and elsewhere.
Xenomorph Android malware
Xenomorph was first detected in early 2022, operating as a banking trojan that targeted 56 European banks via screen overlay phishing. It was distributed via Google Play and the malicious app had over 50,000 installations.
Its creators, the “Hadoken Security” team, continued developing the malware. In June 2022, they released a new version that made the malware modular and more flexible.
In August 2022, ThreatFabric reported that Xenomorph was being distributed via a new dropper named “BugDrop,” which bypassed security features in Android 13.
See also: Stealth Falcon hackers use new Deadglyph malware
In December 2022, the same analysts reported on a new malware distribution platform called “Zombinder,” which embedded the threat into legitimate Android app APK files.
A few months ago, in March 2023, a new third major version of Xenomorph was detected, featuring an automated transfer system (ATS) for autonomous transactions on the device, MFA, cookie theft, and the ability to target over 400 banks.
Xenomorph Android malware: New campaign
In the most recent campaign, which began in August 2023, the operators of the Xenomorph Android malware chose to use pages phishing, luring visitors to update their Chrome browser on their mobile devices. The goal was to download the malicious APK.
According to researchers, the malware continues to use overlays to steal information. However, it has now expanded its targeting scope to include banks from the United States and multiple crypto apps.

ThreatFabric explains that each Xenomorph sample is loaded with around a hundred overlays that target different sets of banking and crypto apps, depending on the targeted demographic.
“[..]this latest campaign also added multiple financial institutions from the United States, along with multiple crypto wallet applications, totaling over 100 different targets per sample, each using a specially crafted overlay to steal valuable PII from the victim’s infected device,” says ThreatFabric.
See also: BBTok trojan: Targets customers of 40 banks in Latin America
New version of malware
Although the new Xenomorph specimens are not much different from previous variants, they do possess some new features.
First, there is a new “ mimic ” feature , which can be activated with a corresponding command, so that the malware can act like another application .
This feature also has another activity called IDLEActivity, which acts as a WebView to display legitimate web content from within a trusted process. This way, there is no need to hide icons from the startup application after installation (which is flagged as suspicious behavior by most security tools).
Another new feature is “ClickOnPoint,” which allows operators of the Xenomorph Android malware to simulate taps at specific screen. This allows operators to bypass confirmation screens or perform other simple actions without using the full ATS module, which can result in security.
Finally, there is a new “antisleep” system that prevents the device from turning off screen . This is useful for avoiding interruptions that require the restoration of command and control communications.

Other findings
ThreatFabric security researchers were able to gain access to the attackers' payload hosting infrastructure and discovered other malicious payloads in addition to the Xenomorph Android malware. Some of these included Android variants of the Medusa and Cabassous malware, Windows information stealers RisePro and LummaC2 , and the Private Loader malware loader.
The above shows that we should be very careful with notifications on mobile phones that talk about a supposed update to browser , as they are likely to be part of malware distribution campaigns.
See also: TikTok: Fake celebrity videos with Temu codes
The distribution of Xenomorph alongside powerful Windows malware suggests collaboration between attackers or the possibility of selling the Android trojan as Malware-as-a-Service (MaaS).
Android malware, such as Xenomorph, is an ever-growing threat to mobile devices. Despite improvements in security, attackers are constantly finding new ways to bypass security and compromise devices. It is important for users to stay up to date with the latest threats and use antivirus protection, keep their apps and operating system updated, and be careful about the websites and messages they open.
Source: www.bleepingcomputer.com
