The new Snowblind malware abuses a security feature to bypass existing protections on Android devices and steal sensitive data user

Snowblind's goal is to modify a target application so that it cannot detect misuse of accessibility services. This allows the malware to obtain user information, such as credentials, or gain remote access to perform malicious actions.
What makes the Snowblind malware different is that it abuses "seccomp" (secure computing), a Linux kernel that Android uses to perform checks on applications and protect users from malicious actions, such as application repackaging (which is what this malware does).
See also: Android: New Medusa banking trojan attacks
Snowblind malware: Abuse of seccomp
Security firm Promon was able to analyze how Snowblind achieves its goal without being detected.
“This malware attacked the application of an i-Sprint customer in Southeast Asia. Our analysis of Snowblind found that it uses a new technique to attack applications Android,” the company said.
Seccomp is a Linux kernel security feature designed to enhance the security of applications by restricting the system calls (syscalls) they can make. It acts as a filter for the syscalls that are allowed to be executed in an application, excluding those that have been used in attacks.
Google first integrated seccomp in Android 8 (Oreo), implementing it in the Zygote process (the parent process of all Android applications).
The Snowblind malware targets applications that handle sensitive data by injecting a native library that loads before the anti-tampering code. It installs a seccomp filter to intercept system calls, such as the "open() syscall", which is commonly used for file access.
When the target app's APK is checked for a violation, the Snowblind malware's seccomp filter prevents the call from continuing and instead triggers a SIGSYS signal, indicating that the process sent a bad argument to the system call.
See also: Singapore: Two men charged with distributing Android malware
Snowblind also installs a signal handler for SIGSYS. This way, the malware can modify the 'open()' system call arguments to direct the anti-tampering code to an unmodified version of the APK.

Promon researchers say that the technique used in Snowblind attacks “ does not appear to be well-known ,” so many applications are not protected against it.
According to researchers, users don't understand anything and the Snowblind malware easily steals credentials from devices.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Researchers told BleepingComputer that Snowblind can be used to disable various security in apps, such as two-factor authentication or biometric verification.
An attacker could use the technique “to read sensitive information displayed on the screen, navigate the device or control applications, bypass security measures, as well as steal sensitive personal information and transaction data.”
See also: Malware campaign targets Windows, Android and macOS
Snowblind malware is just one of many emerging Android attack vectors that highlight the need for users and developers to remain vigilant against evolving threats cyber. By understanding how these attacks work and taking proactive steps to protect personal devices, we can mitigate the impact of such malicious activities. As technology continues to advance, it is important to stay informed and take the necessary precautions to protect our digital lives. So, being aware of new threats like Snowblind can go a long way in keeping our devices and data safe.
Source: www.bleepingcomputer.com
