HomeSecurityFake IPTV apps distribute Android malware Massiv

Fake IPTV apps distribute Android malware Massiv

Cybersecurity researchers have revealed details of a new Android trojan called Massiv, which is designed to facilitate device takeover (DTO) attacks with the aim of stealing financial data and money.

 IPTV Android malware Massiv

The malware, according to ThreatFabric, mimics seemingly harmless IPTV applications to trick victims, indicating that the activity primarily targets users looking for online TV applications.

“ This new threat, although only observed in a limited number of targeted campaigns, already poses a major risk to mobile banking, allowing its operators to remotely control infected devices and carry out attacks device takeover with further fraudulent transactions from victims’ bank accounts users ,” the Dutch mobile security firm said

See also: CRESCENTHARVEST: New campaign targets supporters of protests in Iran

Massive Android malware

The Android banking malware Massiv supports a wide range of functions to facilitate credential theft through multiple methods: screen streaming via Android's MediaProjection API, keystroke logging, SMS interception , and fake overlays on top of banking apps. The fake pages ask users to enter their credentials and credit card details.

One such campaign has been found targeting gov.pt, a Portuguese public administration app that allows users to store identification documents and manage their Digital Mobile Key (also known as Chave Móvel Digital or CMD). The overlay attack tricks users into entering phone number and PIN, likely in an attempt to bypass Know Your Customer (KYC) verification.

ThreatFabric reported that it has identified cases where scammers used the information captured through these overlays to open new bank accounts in the victim's name. These accounts were used for money laundering or loan approval without the victim's knowledge.

Fake IPTV apps distribute Android malware Massiv

The Massiv malware also acts as a remote control tool, allowing the operator to access the victim's device covertly, while displaying a black overlay screen to hide the malicious activity. These techniques, which are carried out by abusing Android's accessibility services, have also been observed in several other Android bankers such as Crocodilus, Datzbro, and Klopatra.

“However, some applications implement protection against screen recording,” the company explained. “To bypass this, Massiv uses the so-called UI-tree function — it traverses AccessibilityWindowInfo roots and recursively processes AccessibilityNodeInfo objects.”

See also: Copilot and Grok are used as Malware C2 Proxies

This is done to create a JSON representation of the visible text and content descriptions, UI elements, screen coordinates, and interaction flags, which indicate whether the UI element is clickable, editable, focused, or activated. Only nodes that are visible and have text are output to the attacker, who can then determine the next course of action by issuing specific commands to interact with the device.

The malware is equipped to perform a wide range of malicious actions:

– Enable black overlay, mute sounds and vibrations

– Send device information

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

– Perform click and swipe actions

– Change the clipboard with specific text

– Disable black screen

– Enable/disable screen streaming

– Unlock device with pattern

– Provide overlays for application, device pattern lock or PIN

– Download ZIP file with overlays for targeted applications

– Download and install APK files

– Open Battery Optimization, Device Admin, and Play Protect settings screens

– Request access rights to SMS messages, install APK packages

– Clear logging databases on the device

See also: Keenadu: New backdoor detected in Android firmware

Fake IPTV apps distribute Android malware Massiv

Massiv is distributed in the form of dropper applications that mimic IPTV applications via SMS phishing. Once installed, the dropper asks the victim to install an “important” update, which grants it permissions to install software from external sources. The names of the malicious objects are listed below:

– IPTV24 (hfgx.mqfy.fejku) – Dropper

– Google Play (hobfjp.anrxf.cucm) – Massiv

“In most of the observed cases, it is just a pretense,” ThreatFabric said. “No real IPTV apps were infected, and none contained any malicious code to begin with. Typically, the dropper that imitates an IPTV app opens a WebView with an IPTV website, while the real malware is already installed and running on the device.”

Massiv is the latest threat to enter an already crowded Android threat landscape.

“While it has not yet been observed to be promoted as Malware-as-a-Service, the Massiv operator shows clear signs of pursuing this path, introducing API keys that will be used in the malware’s communication with the backend,” ThreatFabric said. “Code analysis revealed continued development, with more capabilities likely to be introduced in the future.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS