HomeSecurityBrokewell: A new dangerous Android banking trojan

Brokewell: A new dangerous Android banking trojan

Researchers have discovered a new Android banking trojan, which they have named Brokewell. This trojan records everything that happens on the device (touches on the screen, information displayed, text input, applications opened, etc.).

Brokewell Android banking trojan

The Brokewell trojan is delivered via a fake Google Chrome updatethat appears when using the browser. It is still in development and has many features that allow attackers to take control and manipulate the vulnerable Android device.

Brokewell: Details about the Android banking trojan

According to ThreatFabric, Brokewell is distributed via a fake Chrome update. Examining previous campaigns, researchers discovered that Brokewell had previously been used to target “buy now, pay later” financial services (e.g. Klarna) and posed as an Austrian digital identification app called ID Austria.

See also: SoumniBot: Beware! New Android banking malware

Essentially, the Android trojan Brokewell steals data and offers remote control capabilities to attackers.

Data theft occurs in various ways:

  • Mimics login screens of targeted applications to steal credentials
  • It uses its own WebView to intercept and extract cookies (after a user logs in to a legitimate website)
  • Records the victim's movements on the device (taps, text inputs, etc.) to steal sensitive data
  • Gathers hardware and software details about the device
  • Recovers call logs
  • Determines the physical location of the device
  • Records audio

Device control and operation:

  • Android banking trojan Brokewell allows attacker to view target device screen in real time
  • Performs touch and swipe gestures remotely
  • Allows remote clicking on specified elements
  • Simulates physical button presses (e.g. Back, Home, and Recents)
  • Allows remote scrolling within elements
  • Allows text to be typed into specified fields
  • Activates the screen remotely
  • Adjusts settings such as brightness and volume

See also: PixPirate banking trojan targets users in Brazil

Brokewell: A new dangerous Android banking trojan

Who is behind the Android banking trojan Brokewell?

ThreatFabric reports that someone calling himself Baron Samedit is behind Brokewell . Researchers have discovered another tool called “ Brokewell Android Loader ,” also developed by the same individual. The tool is used by many cybercriminals.

Interestingly, this program can bypass the restrictions introduced by Google in Android 13 and later versions.

Security researchers warn that Brokewell's capabilities are in high demand among cybercriminals because they allow them to execute the scam from the victim's device, thus avoiding assessment and detection tools.

They expect Brokewell to be further developed and offered to other cybercriminals on hacking forums.

See also: CHAVECLOAK: New banking trojan targets users in Brazil

Protection from banking trojan

One of the most effective techniques for protecting against Android Banking Trojans is to use a reliable security. This should include a strong antivirus and anti-malware engine.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, it is important to keep your operating system and all your applications up to date. Updates often include security that can protect your device from the latest known Banking Trojans.

Brokewell: A new dangerous Android banking trojan

Education strategy . Users need to be aware of the risks associated with Banking Trojans, such as Brokewell, and they need to know how they can infect their phones. This can include learning how to recognize and avoid attacks .

In the case of Android, it is also essential to download applications only from trusted sources, such as Google Play.

Finally, using complex passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your accounts, even if they manage to get your password.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS