HomeSecurityNew trojan “BingoMod” targets Android devices

New trojan 'BingoMod' targets Android devices

Cybersecurity researchers have discovered a new trojan (RAT) for Android, called "BingoMod".

BingoMod Android

This malware not only makes fake money transfers from compromised devices, but also attempts to erase its tracks by erasing their data.

Italian cybersecurity firm Cleafy, which discovered the RAT in late May 2024, reported that this malware is constantly evolving and attributed the Android trojan to a possible hacker from Romania, due to the fact that the comments in the source code associated with the initial versions are written in Romanian.

Read more: Gh0st RAT Trojan: Targets Chinese Windows Users via Fake Chrome Site

"BingoMod belongs to the modern generation of Android RAT malware , as its remote access capabilities allow hackers to perform account takeovers (ATO) directly from the infected device, exploiting the on-device fraud (ODF) technique," Alessandro Strino and Simone Mattia reported.

It is also noteworthy that this technique has been observed in other Android banking trojans, such as Medusa (also known as TangleBot), Copybara and TeaBot (also known as Anatsa).

“BingoMod”, like “BRATA”, is notable for its use of a self-destruct mechanism designed to remove any traces of malicious activity from the infected device, thus preventing their analysis. Although this functionality is limited to the device’s external storage, it is suspected that the remote access capabilities could be used to perform a full factory reset.

Some reputable apps masquerade as antivirus tools or Google Chrome updates. Once installed, they ask the user to grant permissions to access accessibility services, which hackers exploit to perform malicious actions.

See also: Adobe: New Generative AI capabilities in Illustrator and Photoshop

This involves executing the main payload and logging the user off the main screen to collect device information, which is then transferred to a server controlled by the hackers. In addition, the hackers exploit the accessibility services API to steal sensitive information displayed on the screen, such as credentials and remaining bank account details, and gain permission to intercept SMS messages.

To initiate money transfers directly from compromised devices, “BingoMod” establishes a socket-based connection to the command and control (C2) infrastructure. This allows it to receive up to 40 remote commands to take screenshots via Android’s Media Projection API, as well as interact with the device in real time.

This also means that the ODF technique requires the involvement of a “live” operator to transfer funds up to €15,000 per transaction, as opposed to using an Automated Transfer System (ATS), which can allow financial fraud on a larger scale.

BingoMod Android

Another critical aspect of the hackersis their emphasis on avoiding detection, using code obfuscation techniques, as well as the ability to uninstall arbitrary applications from the compromised device. This suggests that malware creators prioritize simplicity over advanced features.

Read also: 9002 RAT malware targets Italian companies

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“In addition to real-time screen monitoring, the malware features phishing via overlay attacks and fake notifications,” the researchers said. “Typically, overlay attacks are not triggered when the target applications are opened, but are launched directly by the malware operator.”

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS