HomeSecurityAndroid banking trojans imitate government applications

Android banking trojans mimic government apps

A sophisticated malware campaign has emerged, targeting Android users in Indonesia and Vietnam with banking trojans disguised as legitimate government identity apps and payment services.

banking trojans

This malicious operation, active since approximately August 2024, uses advanced evasion techniques to distribute variants of the BankBot, while maintaining an extensive infrastructure with over 100 domains.

Threat actors demonstrate significant operational sophistication through the use of fake Google Play Store pages and government applications such as M-Pajak tax payment services and digital identity verification systems.

The campaign exploits users' trust in official government platforms, creating highly convincing fakes that trick victims into downloading malicious APK files containing banking trojans capable of stealing sensitive financial information and credentials.

See also: BMC vulnerabilities allow bypass of Signature Verification

DomainTools analysts identified the malware distribution pattern by monitoring suspicious website elements associated with fake Google Play Store pages.

Android banking trojans mimic government apps
Android banking trojans mimic government apps

Researchers uncovered a sophisticated distribution mechanism designed to bypass traditional network security controls and evade automated detection commonly used by cybersecurity frameworks.

Threat actors leverage WebSocket technology to bypass conventional security measures. Instead of providing direct download links that can be easily detected by security scanners, malicious websites use the Socket.IO library to create real-time, two-way communication channels between victims' browsers and command-and-control servers.

When users click the Android download button , the system initiates a WebSocket connection using the socket.emit('startDownload', …) command.

The server responds by transmitting the malicious APK file in chunks, rather than a complete file transfer. The browser collects these chunks via event listeners coded as socket.on('chunk', (chunk) => { chunks.push(chunk); }), while simultaneously receiving progress updates that maintain the illusion of a legitimate download.

See also: BRICKSTORM: Chinese hackers had access to American companies for a year

Upon completion, the system combines all the downloaded pieces in memory and assigns the MIME type application/vnd.android.package-archive to create a correct APK file structure.

The distribution mechanism then creates a temporary local URL and triggers an invisible download link, triggering the browser's standard file download interface.

This complex process effectively disguises malware distribution as encrypted WebSocket traffic, allowing malicious payloads to bypass network security systems configured to block direct APK downloads, while remaining invisible to static URL security scanners that scan websites for malicious links.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Android banking trojans mimic government apps

Banking trojans: Danger for users

The incident demonstrates two critical trends: First, attackers exploit trust in official services — with fake government apps and fake Play Stores — to convince victims to install “alternative” APKs. Second, the use of real-time socket transmissions (Socket.IO/WebSocket) allows payloads to be delivered in batches, bypassing static URL scanners and making network analysis more demanding.

See also: Chinese Hackers RedNovember Target Global Governments

Defensively, the message is clear: users should avoid third-party installations and check digital certificates and reviews on the official Play Store (to avoid banking trojans). Security organizations should add surveillance for non-standard WebSocket usage, analyze unusual data flows, and filter domains with indicators of malicious infrastructure.

Finally, the incident reminds us that the fight against mobile banking malware is not just technical — it also involves user education, strict management of the “install only from a trusted source” rule, and constant monitoring of infrastructures that use segmented or hidden file delivery routes.

The case demonstrates that cybercriminals move faster than defenses: the more complex the distribution methods, the more critical prevention, constant awareness, and collective vigilance of organizations and users become.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS