HomeSecurityThe Rocinante Trojan is presented as a banking application, with the aim of stealing...

Trojan Rocinante disguises itself as a banking app to steal sensitive data from Android users in Brazil

Mobile phone users in Brazil are being targeted by a new malware, codenamed Rocinante, which delivers a new banking Trojan for Android.

Trojan Rocinante

"This malware family is capable of logging keystrokes via the Accessibility Service and can also steal personally identifiable information (PII) from its victims, using fake screens pretending to be various banks," said Dutch security firm ThreatFabric.

See also: New trojan "BingoMod" targets Android devices

“Furthermore, it can exploit this information to gain control of the device (DTO), leveraging accessibility service privileges and gaining full remote access to the infected device.”

The malware's main targets include financial institutions such as Itaú Shop and Santander, with fake apps pretending to be Bradesco Prime and Correios Celular. These include Livelo Pontos (com.resgatelivelo.cash), Correios Recarga (com.correiosrecarga.android), Bradesco Prime (com.resgatelivelo.cash) and Módulo de Segurança (com.viberotion1414.app).

Analysis of the malware's source code revealed that its operators refer to it internally at Rocinante as Pegasus (or PegasusSpy). It is important to note that the name Pegasus is not related to the spyware developed by NSO Group.

Pegasus appears to have been created by a threat actor known as DukeEugene, who has been noted for developing similar malware, including ERMAC, BlackRock, Hook, and Loot, according to a recent analysis by Silent Push. ThreatFabric reported that it identified parts of Rocinante affected by early versions of ERMAC, although the leak of ERMAC source code in 2023 may have influenced this situation.

“This is the first case where an original malware family adopted code from a leak, incorporating only a portion of it into its own code,” he noted. “It is possible that these two versions are separate forks of the same original project.”

Rocinante is primarily distributed via phishing websites that attempt to trick unsuspecting users into installing fake dropper apps. Once installed, they request accessibility service permissions , allowing them to record all activities on the infected device, monitor SMS messages, and display fake login pages.

Additionally, they establish contact with a command and control (C2) server to await further instructions – simulating touch and swipe events – which will be executed remotely. The personal information collected is mined in a Telegram bot.

Read more: NGate: New Android malware helps hackers steal money

“The bot extracts useful PII obtained through fake login pages, which pretend to be the target banks. It then posts this information, in a form, to a chat that the criminals have access to,” ThreatFabric noted. “The information varies slightly depending on the fake login page used and includes device data such as phone model and number, CPF number, password or account number.”

This development comes as Symantec highlights another banking Trojan malware campaign, which exploits the secure server domain [.]net to target Spanish- and Portuguese-speaking regions.

“The attack begins with malicious URLs that lead to an obfuscated .hta file,” the Broadcom-owned company said. “This file leads to a JavaScript payload that runs multiple AntiVM and AntiAV checks before downloading the final AutoIT payload. This payload is loaded using process injection with the goal of stealing banking information and credentials from the victim’s system and exporting them to a C2 server.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Here’s the scoop on a new “extensionware-as-a-service” service advertised for sale via a recent version of Genesis Market. This platform was shut down due to strict law enforcement in early 2023 and is designed to steal sensitive information from users in the Latin America (LATAM) region, using malicious browser extensions distributed via the Chrome Web Store.

This activity, which began in mid-2023 and targets Mexico and other LATAM countries, has been attributed to a cybercrime group known as Cybercartel, which offers these types of services to other cybercriminal networks. Unfortunately, these extensions are no longer available for download.

“The malicious Google Chrome pretends to be a legitimate application, tricking users into installing it via compromised websites or phishing,” said security researcher Ramses Vazquez of the Metabase Q Ocelot Threat team, representing Karla Gomez.

See also: Gh0st RAT Trojan: Targets Chinese Windows Users via Fake Chrome Site

trojan rocinante brazil

“Once the extension is installed, it injects JavaScript into web pages that the user visits. This code can intercept and modify the content of the pages, as well as extract sensitive data such as login credentials, credit card information, and other personal information, depending on the specific campaign and the type of information targeted.”

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS