A new Android Banking Trojan called SlemBunk has been discovered by the FireEye security team, which targets users in various countries who use mobile banking.
[alert variation=”alert-success”]In addition to ransomware, mobile banking trojans seem to be a favorite “weapon” of cybercriminals during the holidays, with new trojan families being discovered every day.[/alert]
SlemBunk, which was first observed by Fortinet and later analyzed by FireEye researchers, targets at least 33 financial institutions – 31 banks and two online payment systems – primarily targeting banks in Australia and the US.
As with most threats designed for mobile devices, infection is achieved through side-loaded applications, which are downloaded from untrusted sources.
In the case of SlemBunk, users visiting adult websites are tricked into installing a fake version of Flash Player for Android in order to gain access to pornographic material.
In this way, the Trojan is installed on their device, which immediately begins performing a series of nefarious actions, gaining administrator rights, communicating with the C&C server, monitoring active processes, and when the right time comes, injecting a fake login page as part of the genuine targeted banking application.
Once it manages to intercept users' login details, SlemBunk immediately sends them to the C&C server. In addition to financial information, the Trojan is also known to collect other types of data, such as social media and high-profile Android app credentials, contact lists, SMS messages, and various other phone information.
SlemBunk is still active, even now.
When it was first detected, the trojan only had the ability to steal data from social networking apps. However, over the past year, SlemBunk has evolved, and has slowly but steadily begun to expand its capabilities.
“As SlemBunk gradually expanded into the banking sector, its code evolved and became increasingly complex. The rise and evolution of the SlemBunk trojan clearly shows that mobile malware has become more complex and targeted,” the researchers report.
FireEye reports that in total, at least 170 different variants of SlemBunk have been detected, while the latest C&C server detected is very active, which means that users are at risk and are very likely to be infected.

