HomeSecurityiBanking: taking full advantage of the potential of Android Malware

iBanking: taking full advantage of the potential of Android Malware

Powerful Russian cybercriminal gangs have begun using sophisticated Android malware to expand attacks on financial institutions. The tool, known as iBanking, is one of the most expensive malware tools Symantec has detected on the market, and its creator has a Software-as-a-Service business model. 

mobile-iBanking

Behind the alias GFF, the owner sells full subscriptions of the software, with all updates and technical support for up to US$5,000. For those attackers who cannot afford the subscription fee, GFF is prepared to go ahead with an offer, offering rental in exchange for a share of the profits.

iBanking is often disguised as a legitimate social networking, banking application or security solution and is primarily used to bypass out-of-band security measures by cracking passwords sent via SMS. It can also be used to build mobile botnets and conduct surveillance on its victims. iBanking has a number of advanced features, such as allowing attackers to switch control of the device between HTTP and SMS, regardless of the availability of an internet connection.

How it works
Attackers use social engineering tactics to lure their victims into downloading and installing iBanking on their Android devices. The victim is usually already infected with a financial trojan on their computer, which will create a pop-up message when they visit a banking website, asking them to install a mobile app as an added security measure.

The user's phone number and operating system are requested and then a link to download the fake software will be sent to them via SMS. If the user does not receive the message for any reason, the attackers will also provide a direct link and a QR code as alternatives to installing the software. In some cases the malware is hosted on the attacker's servers. In other cases, it is hosted on trusted online app stores.

iBanking can be customized to look like official software from a number of banks and social networks. Once installed on the phone, the attacker has almost complete access to the device and can intercept voice and SMS communications.

History
iBanking has evolved from a simple SMS interceptor to a powerful Android Trojan, capable of intercepting a wide range of information from a compromised device, from voice and SMS communication to voice recording via the phone's microphone.

The main features of iBanking include:

  • Interception of phone information – number, ICCID, IMEI, IMSI, model, operating system
  • Hacking incoming/outgoing SMS messages and uploading the information to the control server
  • Intercept incoming/outgoing phone calls and upload the information to the control server in real time
  • Call forwarding to a number controlled by the attacker
  • Forwarding contacts to the control server
  • Recording via microphone and forwarding it to the control server
  • Sending SMS messages
  • Get device location
  • Access to the folder system
  • Access to the program list
  • Prevent app removal if administrator privileges are enabled
  • Restoring the phone to factory settings if administrator rights are activated
  • Obfuscated code

Protection
Symantec has identified the threat as Android.iBanking. Users should be wary of any SMS message containing a link that prompts them to download APKs (Android application package files), especially if they come from untrusted sources. IT administrators should consider blocking all messages containing a link to install an APK.

Some iBanking APKs have joined trusted marketplaces and users should be aware of this potential infection route. Users should be wary of sharing sensitive data via SMS, or at least be aware that malware is looking for this data.

 

 

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS