HomeSecurityXenomorph Android malware: Targets banking and crypto wallet users in the US

Xenomorph Android malware: Targets banking and crypto wallet users in the US

Researchers have discovered a new Xenomorph malware, targeting Android users in the US, Canada, Spain, Italy, Portugal, and Belgium.

Xenomorph Android malware

Analysts at cybersecurity firm ThreatFabric have been monitoring Xenomorph activity since February 2022. The new campaign, however, began in August of this year.

The latest version of Xenomorph targets users with crypto wallets and customers of various financial institutions in the US and elsewhere.

Xenomorph Android malware

Xenomorph was first detected in early 2022, operating as a banking trojan that targeted 56 European banks via screen overlay phishing. It was distributed via Google Play and the malicious app had over 50,000 installations.

Its creators, the “Hadoken Security” team, continued developing the malware. In June 2022, they released a new version that made the malware modular and more flexible.

In August 2022, ThreatFabric reported that Xenomorph was being distributed via a new dropper named “BugDrop,” which bypassed security features in Android 13.

See also: Stealth Falcon hackers use new Deadglyph malware

In December 2022, the same analysts reported on a new malware distribution platform called “Zombinder,” which embedded the threat into legitimate Android app APK files.

A few months ago, in March 2023, a new third major version of Xenomorph was detected, featuring an automated transfer system (ATS) for autonomous transactions on the device, MFA, cookie theft, and the ability to target over 400 banks.

Xenomorph Android malware: New campaign

In the most recent campaign, which began in August 2023, the operators of the Xenomorph Android malware chose to use pages phishing, luring visitors to update their Chrome browser on their mobile devices. The goal was to download the malicious APK.

According to researchers, the malware continues to use overlays to steal information. However, it has now expanded its targeting scope to include banks from the United States and multiple crypto apps.

Xenomorph Android malware: Targets banking and crypto wallet users in the US

ThreatFabric explains that each Xenomorph sample is loaded with around a hundred overlays that target different sets of banking and crypto apps, depending on the targeted demographic.

“[..]this latest campaign also added multiple financial institutions from the United States, along with multiple crypto wallet applications, totaling over 100 different targets per sample, each using a specially crafted overlay to steal valuable PII from the victim’s infected device,” says ThreatFabric.

See also: BBTok trojan: Targets customers of 40 banks in Latin America

New version of malware

Although the new Xenomorph specimens are not much different from previous variants, they do possess some new features.

First, there is a new “ mimic ” feature , which can be activated with a corresponding command, so that the malware can act like another application .

This feature also has another activity called IDLEActivity, which acts as a WebView to display legitimate web content from within a trusted process. This way, there is no need to hide icons from the startup application after installation (which is flagged as suspicious behavior by most security tools).

Another new feature is “ClickOnPoint,” which allows operators of the Xenomorph Android malware to simulate taps at specific screen. This allows operators to bypass confirmation screens or perform other simple actions without using the full ATS module, which can result in security.

Finally, there is a new “antisleep” system that prevents the device from turning off screen . This is useful for avoiding interruptions that require the restoration of command and control communications.

Xenomorph Android malware: Targets banking and crypto wallet users in the US

Other findings

ThreatFabric security researchers were able to gain access to the attackers' payload hosting infrastructure and discovered other malicious payloads in addition to the Xenomorph Android malware. Some of these included Android variants of the Medusa and Cabassous malware, Windows information stealers RisePro and LummaC2 , and the Private Loader malware loader.

The above shows that we should be very careful with notifications on mobile phones that talk about a supposed update to browser , as they are likely to be part of malware distribution campaigns.

See also: TikTok: Fake celebrity videos with Temu codes

The distribution of Xenomorph alongside powerful Windows malware suggests collaboration between attackers or the possibility of selling the Android trojan as Malware-as-a-Service (MaaS).

Android malware, such as Xenomorph, is an ever-growing threat to mobile devices. Despite improvements in security, attackers are constantly finding new ways to bypass security and compromise devices. It is important for users to stay up to date with the latest threats and use antivirus protection, keep their apps and operating system updated, and be careful about the websites and messages they open.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS