After Whatsapp, Chinese WeChat is the second most popular instant messaging app, used by more than 355 million users worldwide.
However, it appears that the application's fame is also being exploited by cybercriminals to distribute a sophisticated banking trojan, which aims to steal financial information.
WeChat allows users to make payments for additional services and features, but to access these features they must enter their payment card details into the app.
This fact is pushing cybercriminals towards the development of new and more sophisticated banking trojans and malwares, which target users' financial data.
Kaspersky Lab security researchers have identified a banking Trojan, also known as Banker.AndroidOS.Basti.a, that mimics the legitimate WeChat app for Android. Upon installation, it also requests the same permissions (e.g., Internet access, SMS receiving, and other services) as the real WeChat app.
Researchers found that some modules of the malware are encrypted, and this feature makes it more sophisticated than other banking malware of its kind. The authors of the malware have used effective encryption to make it impossible to reverse engineer the code.
However, Kaspersky researchers managed to decode the threat module, analyzing the malware's functions.
Once the fake WeChat app is installed on Android devices, it asks users to enter some useful information, such as phone numbers, payment card numbers, PINS, and other financial details, which are then sent to an email account controlled by the malware's creators.
The specific email and its password were recovered by researchers, as they were included in the application's source code.
In this way, the researchers managed to gain access to the email, finding that there are already enough victims of the malicious application.



