A new Android banking malware named “ SoumniBot ” exploits bugs in the Android manifest extraction and parsing procedure . Thanks to this approach, the malware evades standard security measures of Android phones and steals information. SoumniBot was discovered and analyzed by Kaspersky researchers .

Exploiting the Android parser
Manifest files ( “AndroidManifest.xml”) are located in the root directory of each application and contain details about components (services, broadcast receivers, content providers), permissions, and application data.
According to Kaspersky researchers, the Android banking malware SoumniBot uses three different methods, which include manipulating the compression and size of a manifest file, to bypass analysis checks:
Method 1
SoumniBot uses an invalid compression value when unpacking the APK manifest file. This deviates from the standard values (0 or 8) expected by the Android “libziparchive” library, which has taken on this role.
Instead of treating these values as unacceptable, the Android APK parser recognizes the data as uncompressed due to a bug, allowing the APK to bypass security checks and continue execution on the device.
See also: PixPirate banking trojan targets users in Brazil
Method 2
The second method, used by the Android banking malware SoumniBot, involves misreporting the size of the manifest file in the APK, providing a value larger than the actual one. Since the file has been marked as uncompressed in the previous step, it is copied directly from the archive, with junk “overlay” data making up the difference.
This extra data does not directly harm the device, as Android ignores it, but it does confuse code analysis tools.
Method 3
The third avoidance technique is to use very long strings for the names of XML namespaces in the manifest file. As a result, automated parsing tools have difficulty checking them.
Kaspersky researchers informed Google about the inability of APK Analyzer (the official Android analysis utility) to handle files that use the above escape methods.
Android banking malware SoumniBot
Upon startup, SoumniBot requests its configuration parameters from a hardcoded server address and sends profile information about the infected device.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: CHAVECLOAK: New banking trojan targets users in Brazil
It then launches a malicious service that transmits stolen data of the victim every 15 seconds. The stolen data includes IP addresses, contact lists, account details, SMS messages, photos, videos, and online banking digital certificates.
Data theft occurs after the malware receives a command from an MQTT server. Other commands include:
- Delete existing or add new contacts
- Send SMS message (forwarding)
- Setting ringtone volume levels
- Turn silent mode on or off
- Enable or disable debugging on your device
Researchers have not discovered how the Android banking malware SoumniBot reaches target devices. It could be embedded in seemingly legitimate apps in third-party Android stores, or introduced through a later update to legitimate apps. It could also be downloaded from untrusted websites or using some phishing technique.

SoumniBot primarily targets Korean users and hides its icon after installationto make it more difficult to remove. However, it remains active in the background, stealing data from the victim.
See also: Hackers abuse Google Cloud Run to distribute banking trojans
Protection from Android banking malware
- Installing antivirus software is essential for protecting your device. These software can identify and remove malware before it can cause damage.
- It's important to keep your operating system and applications up to date. Updates often include security fixes that can protect your device from malware.
- Avoid installing apps from third-party sources. apps have not undergone the same security checks as those on the Google Play Store and may contain malware (e.g. SoumniBot).
- Pay attention to the permissions apps ask for. If an app asks for access to personal information that doesn't seem necessary, it may be best not to install it.
- Be wary of phishing messages that may try to trick you into downloading malware. These messages may appear to come from legitimate sources, but they often contain links or attachments that can install malware on your device.
- Finally, it is important to regularly back up your data. This can help restore your information if your device is infected with malware (e.g. SoumniBot).
Source: www.bleepingcomputer.com
