HomeYoutubeDroidBot: Android malware steals credentials from banking apps

DroidBot: Android malware steals credentials from banking apps

Security researchers have discovered a new Android banking malware, dubbed “DroidBot,” which is designed to steal credentials from more than 77 crypto exchange apps and banking applications.

According to Cleafy, DroidBot has been active since June 2024 and operates as a malware-as-a-service (MaaS) platform. Cybercriminals can use it through a $3,000/month subscription.

At least 17 groups have used malware builders to tailor their payloads for specific targets.

DroidBot is nothing special compared to other Android banking malware, but analysis of one of its botnets revealed 776 unique infections in the UK, Italy, France, Turkey, and Germany.

See also: TrickMo: Android Banking Malware that Attacks Users to Steal Login Credentials

DroidBot Android banking malware

Cleafy also says that the malware appears to be under development with the aim of expanding to new regions, including Latin America.

DroidBot MaaS

The developers of the Android banking malware DroidBot, who are likely Turkish, provide partners with all the tools needed to carry out effective attacks. These tools are the malware builder, command and control (C2) servers, and a central management panel from which criminals can control their operations, retrieve stolen data, and issue commands.

The payload builder allows affiliates to customize DroidBot to target specific applications, use different languages, and specify other C2 server addresses.

See also: Google Play: Malicious QR reader app distributed banking malware Anatsa

Overall, the DroidBot MaaS feature allows criminals with little knowledge and skills to carry out effective attacks.

Emulating popular apps

The Android banking malware DroidBot often disguises itself as popular applications, such as Google Chrome, the Google Play store, or "Android Security" to trick users.

However, in all cases, it functions as a trojan that tries to steal sensitive information from applications.

The main characteristics of malware are:

  • Keylogging – Keystroke recording.
  • Overlaying – Displaying fake login pages over legitimate banking application interfaces.
  • SMS interception – Hacking into incoming SMS messages, particularly those containing one-time passwords (OTPs) for banking logins.
  • Virtual Network Computing – The VNC module gives collaborators the ability to remotely view and control the infected device, execute commands, and darken the screen to hide malicious activity.

Furthermore, a key aspect of DroidBot's operation is the abuse of Android's Accessibility Services.

See also: SoumniBot: Beware! New Android banking malware

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

DroidBot: Android malware steals credentials from banking apps

As we mentioned earlier, DroidBot steals credentials for 77 crypto and banking apps. Some of these apps are: Binance, KuCoin, BBVA, Unicredit, Santander, Metamask, BNP Paribas, Credit Agricole, Kraken, and Garanti BBVA.

Protection from malicious applications

Users should only download apps from official stores and always confirm the authenticity of an app before installing it. This can be done reviews user.

Additionally, users can visit the official website of a service and find the link there to download the application from the app store.

It's also important to check the permissions that apps request, even if they're in legitimate stores. If an app asks for access to personal information that doesn't seem necessary for it to function, it's best to avoid installing it.

It is also essential to use reliable security software and regularly update the operating system and applications. Finally, users should avoid sharing their personal information with untrusted sources.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS