HomeSecurity6 new Android malware targets banking apps

6 new Android malware targets banking apps

New findings from cybersecurity researchers reveal the emergence of six new Android malware, further amplifying the already growing threat to mobile device users. The malware is designed to steal sensitive data, gain remote control of devices, and facilitate financial fraud, with a particular focus on banking and cryptocurrency transactions.

Android malware banking apps

The new families include banking trojans and remote access tools (RATs). Among them are PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, Oblivion RAT and SURXRAT, which display sophisticated attack and activity concealment techniques.

PixRevolution: Targeting direct payments in Brazil

One of the most dangerous samples detected is PixRevolution, which targets the Pix instant payment platform in Brazil. The malware remains hidden on the device until the user initiates a money transfer.

A mechanism screen-monitoring , allowing the attacker to see the user's movements in real time. When the victim enters the amount and recipient details, the trojan displays a fake loading screen. However, in the background, it replaces the payment key with the attacker's, diverting the money transfer.

See also: SURXRAT: The expansion of an LLM-based Trojan into Android Malware

From the user's perspective, the process seems perfectly normal. The app simply displays a short waiting message and then confirms that the transaction was successful. The problem is only discovered much later, when it is discovered that the money has been sent to the wrong account.

Cybercriminals are spreading malware through fake app pages that mimic the Google Play Store. Users are tricked into installing malicious APK files that impersonate well-known services.

After installation, the apps ask the user to enable accessibility services . This permission allows the malware to gain extensive control over the device, monitor the screen, record keystrokes, and execute commands in the background.

Infected phones also connect to remote servers via TCP to send device information and receive commands from the attack operators.

PixRevolution Android malware targets Pix payment systems

BeatBanker: Banking trojan with hidden cryptocurrency mining

Another dangerous campaign that mainly targets users in Brazil is BeatBanker. The malware is mainly spread through phishing websites that pretend to be the Google Play Store.

See also: ClipXDaemon Malware: New Crypto Clipboard Hijacker on Linux

BeatBanker's special feature is an unusual persistence mechanism. The program continuously plays a nearly silent audio file of a few seconds, so that the operating system does not terminate its process.

The malware also integrates a cryptocurrency miner and bank fraud. When the user attempts to make transactions on platforms such as Binance or Trust Wallet, the trojan creates fake overlay screens that replace the recipient's address with that of the attacker.

PixRevolution Android malware targets Pix payment systems

TaxiSpy RAT and Mirax: Complete device surveillance

TaxiSpy RAT is a combination of a banking trojan and a remote administration tool. The malware collects SMS messages, contacts, call logs, clipboard data, and app notifications.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, it can intercept lock screen PINs and record keystrokes, allowing attackers to gain a complete picture of the user's activity.

Mirax , on the other hand, is available as a malware service -as-a-service (MaaS) , with a subscription that can cost up to $2,500 per month. The package includes tools for keystroke logging, SMS interception, and proxy creation via infected devices.

Oblivion RAT malware

A new remote access trojan for Android, called Oblivion, is selling for about $300 a month (or $1,900 a year and $2,200 for lifetime access) and claims to bypass detection and security features on devices from major manufacturers.

See also: Fake IPTV apps distribute Android malware Massiv

Once installed, the malware uses an automated permission granting mechanism that requires no interaction from the victim. This approach works on MIUI/HyperOS (Xiaomi), One UI (Samsung), ColorOS (OPPO), MagicOS (Honor), and OxygenOS (OnePlus).

New techniques with artificial intelligence and ransomware

Among the most worrying developments is SURXRAT, an advanced version of previous Android RATs distributed via MaaS networks on Telegram.

Some versions of the malware include experimental features based on large AI language models. These features appear to be used to automate attacks and analyze data from infected devices.

In some cases, the malware can even lock the user's device by displaying a ransomware-style message and demanding payment to restore access.

6 new Android malware targets banking apps

The new reality of cybersecurity on smartphones

The emergence of so many new malware families shows that attackers are increasingly investing in mobile devices. As smartphones are now used for banking, digital payments and storing personal data, they are a particularly attractive target.

Experts recommend that users install apps only from trusted sources, avoid enabling accessibility permissions for unknown apps, and keep their operating system up to date. With threats constantly evolving, mobile device security is now as important as that of computers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS