HomeSecurityTrickMo: Android Banking Malware Attacks Users to Steal Login Credentials

TrickMo: Android Banking Malware Attacks Users to Steal Login Credentials

Android banking malware is a type of malware that targets financial institutions and their customers.

TrickMo malware

There is an increase in Android banking malware, which exploits vulnerabilities in the Android operating system to steal sensitive user information.

Cleafy's Threat Intelligence team recently discovered a new Android banking malware called “TrickMo”, which was found to be actively attacking users to steal login credentials.

Android Banking Malware TrickMo

Read more: SpyAgent: New Android malware steals crypto wallet recovery phrases

TrickMo is a new variant of Android banking malware, derived from its predecessor, TrickBot. Instead of traditional coders, it leverages advanced anti-analysis techniques, such as broken zip files, jsonpacker, and dropper applications, to evade detection.

This malware is distributed via a dropper disguised as “Google Chrome” and exploits Android Accessibility Services to approve administrative controls. Once installed, TrickMo has the ability to capture one-time passwords for online banking services, record screens, log keystrokes, and exploit remote access to infected devices.

It engages in data exchange with the C2 server using the post method and sending device information as JSON to the /c endpoint and receives commands, according to the Cleanfly report.

TrickMo uses a Clicker configuration (clicker.json) to automate actions through the Accessibility Service, targeting both system and utility apps.

The malware has capabilities such as SMS interception, photo retrieval, screen recording, remote access and HTML overlay attacks to steal credentials. The malware has the ability to change the default SMS app, retrieve lists of installed apps and perform clicks and various actions on the device.

TrickMo's C2 server maintains data, such as logs, credentials, and photos, but lacks any form of authentication, exposing victims to multiple threat actors.

TrickMo was first discovered and reported by CERT-Bund in 2019, primarily targeting banking applications in Europe, with an emphasis on the German language, as indicated by the specific language settings in the Clicker.json file.

See also: NGate: New Android malware helps hackers steal money

Analysis of the package name of Cloud Strife's installer (dreammes.ross431.in) and its unpacking process (com.turkey.inner.Uactortrust) reveals the highly advanced methods used to hide and protect the malware.

The breach occurred due to the misconfiguration of the Command and Control (C2) server, which led to the leakage of 12 GB of the victim's data.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Some critical endpoints of the C2 server revealed the IP addresses of compromised devices, operation logs, and HTML documents used for attacks on banking and cryptocurrency.

Additionally, they included CSV files with stolen usernames and passwords, as well as ZIP files containing images of compromised devices.

This leak not only reveals a tactical error by the creators of TrickMo's infrastructure, but also increases the possibility of further exploitation of the leaked data.

TrickMo android banking malware

Read more: Singapore: Two men charged with distributing Android malware

Threat actors can leverage this information to log into user accounts, commit identity theft, and execute targeted phishing. The published information includes both the attack and potential physical targets, indicating the need for comprehensive security measures.

It is therefore imperative to improve data security systems to prevent such incidents in the future.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS