Security researchers at Zimperium have uncovered the expansion of a distribution campaign of an Android mobile banking Trojan targeting major Iranian banks.

This campaign was originally discovered in July 2023 and has now evolved to add more and improved capabilities, according to a new report by Zimperium analysts Aazim Bill SE Yaswant and Vishnu Pratapagiri
See also: North Korean hackers combine macOS malware tactics to evade detection
A previous investigation by the company identified four groups of apps that impersonated major Iranian banks and stole user credentials. apps , which were actually banking Trojans, were released between December 2022 and May 2023. The apps could steal credentials and credit card information, while also hiding their icons on the victim's device to prevent uninstallation and intercepting SMS messages for one-time password (OTP) codes.
Zimperium's latest findings include the identification of 245 new application variants related to the same threat actors. Notably, 28 of these variants remain undetected by tools .
Researchers have noticed that the new variants are expanding the reach of the campaign, targeting more banks. The malware is now showing interest in collecting information about various cryptocurrency wallet, which means that the attackers probably want to target them as well.
See also: NukeSped Malware Exploits Apache ActiveMQ Vulnerability
New capabilities were also identified, such as the abuse of accessibility services for overlay attacks, automatic granting of permissions to access SMS , and methods for extracting data using GitHub repositories. Zimperium also highlights specialized attacks on Xiaomi and Samsung devices, while there is also a possible interest in targeting iOS devices.

Researchers Yaswant and Pratapagiri stressed the importance of protecting mobile devices.
“It is obvious that modern malware is becoming more sophisticated and its targets are expanding, so runtime visibility and protection are crucial for mobile applications ,”the researchers explained.
Android Trojan attacks can have serious consequences for users . They can cause serious financial damage, as malicious users can gain access (thanks to stolen credentials) to accounts and steal money.
See also: Mobile malware: A major risk for businesses
Furthermore, these attacks can create disruption in the country's financial system in general, as banks are vital to the functioning of the economy and attacks on users can create significant issues.
Furthermore, Android Trojan attacks can undermine citizens' trust in the financial system, as malicious users can steal personal data and cause damage to their accounts.
Source: www.infosecurity-magazine.com
