HomeSecurity10 new Android banking trojans appeared in 2023

10 new Android banking trojans appeared in 2023

The end of 2023 is approaching, and a recent report showed that ten new Android banking trojans emerged this year , collectively targeting 985 apps banking and fintech/trading from financial institutions in 61 countries .

Android banking trojans 2023

Banking trojans are malicious software that targets people's online banking accounts and money, stealing credentials and session cookies, bypassing 2FA protections, etc.

In addition to the ten new trojans, 19 more banking malware from 2022 were modified to add new capabilities and continue their attacks more effectively.

See also: Android banking trojan expands attacks on Iranian banks

Security firm Zimperium analyzed all 29 malware (10 + 19) and reported that emerging trends include:

  • The addition of an automated system (ATS) that steals MFA tokens, authorizes transactions, and executes fund transfers.
  • The use of social engineering, where cybercriminals pose as bank customer support employees and direct victims to download banking trojan payloads.
  • Adding live screen-sharing for direct remote interaction with the infected device.
  • Offering the malware in a subscription package to other cybercriminals .

Of course, there are still the usual features, such as keylogging, phishing messages, and SMS message theft.

A worrying development, according to Zimperium, is that many banking trojans are not only targeting banking credentials and money anymore, but also social media, messages, and personal data.

See also: Zanubis: Android banking trojan becomes even more dangerous

10 new Android banking trojans

Zimperium examined ten new trojans with more than 2,100 variants. They appear as special utilities, productivity apps, entertainment portals, photography tools, games, and educational aids to cover up their malicious activity and attract victims.

  • Nexus: MaaS (malware-as-a-service) with 498 variants. Targets 39 applications in nine countries.
  • Godfather: MaaS with 1,171 known variants targeting 237 banking apps in 57 countries.
  • Hook: MaaS with 14 known variants. Targets 468 applications in 43 countries and is rented to cybercriminals.
  • Saderat: Trojan with 300 variants targeting eight banking applications in 23 countries.
  • Pixpirate: Trojan with 123 known variants. Targets ten banking applications.
  • Vultur: Trojan with nine variants targeting 122 banking applications in 15 countries.
  • Xenomorph v3: MaaS functionality with six variants. Targets 83 banking applications in 14 countries.
  • GoatRat: Trojan with 52 known variants that targets six banking applications.
  • BrasDex: Trojan targeting eight banking applications in Brazil.
  • PixBankBot: Trojan with three known variants targeting four banking applications.

Regarding the malware used since 2022, the most active and dangerous are Teabot, Exobot, Mysterybot, Medusa, Cabossous, Anubis and Coper.

Finally, the most targeted countries are the United States (109 targeted banking apps), the United Kingdom (48 banking apps), Italy (44 apps), Australia (34), Turkey (32), France ( 30), Spain (29), Portugal (27), Germany (23) and Canada (17).

banking malware

Protection from Android banking malware

To protect yourself, start by installing a reputable antivirus program on your Android device. This program will help you detect and remove any malware that may be present on your device. Choose an antivirus program from a reputable provider and update it frequently to maintain its effectiveness.

See also: Banking malware: The most dangerous trojans that have ever existed!

Another important way to protect yourself from Android banking trojans is to avoid installing apps from untrusted sources . By only downloading apps from the official Google Play store, you reduce the risk of downloading malware. You should also check user ratings and comments before downloading an app to make sure it is safe.

Additionally, it's important to be careful with permission requests that apps make during installation. If an app requests access to personal data or device functions that don't seem relevant to its operation, then it's a good idea to be cautious and decide whether you want to grant those permissions.

Finally, it's important to operating system your device's and apps on a regular basis. Updates often include security patches that can protect your device from known malware. Make sure you have automatic updates enabled to ensure you're getting the latest security patches.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS