Android banking malware source code published
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Security researchers believe that this particular code has the potential to cause a spike in the number of attacks involving Android banking Trojans. Attackers may take advantage of the malicious code to attack banks around the globe. Currently, this particular variant has been found targeting only users of Russian banks.
The new malware is distributed under the guise of benign programs for example, Google programs with the Play Store icon. Once the device user installs and runs Bankbot, it prompts the user to grant it administrator privileges to thwart its removal from the system. Once obtained, the Trojan removes the app's icon from the phone's home screen in order to trick victims into believing it was removed. However, it will still remain active in the background, waiting for commands from attacker's command and control (C&C) server. BankBot has the ability to perform a broad range of tasks, including send and intercept SMS messages, make calls, track devices, steal contacts, show phishing dialogs and steal sensitive information, like banking and credit card details.
Bankbot has the ability to conceal itself until the victim opens up a targeted mobile banking or social media app. Once opened, the malware launches a phishing login overlay, which allows the Trojan to store user credentials as it displays the information on top of the attacked application. Bankbot will then prompt victims to re-authenticate or re-enter their payment card details. The Trojan not only steals mobile banking login credentials but also bank card information belonging to the owner of the compromised device which is why it tracks the launch of certain apps so it can phish credentials. The apps being targeted include Facebook, WhatsApp, Instagram, Twitter, YouTube, Snapchat, Viber, WeChat, imo, Uber and the Google Play Store.
In addition, the BankBot Trojan can also intercept text messages, send them to the attackers and then delete them from the victim's smartphone, which means bank notifications never reach the users.
Bankbot scans smartphones and tablets for the presence of the following banking applications and payment systems:
Sberbank Online
Sberbank Business Online
Alfa-Bank
Alfa-Business
Visa QIWI Wallet
R-Connect mobile bank
Tinkoff
PayPal
WebMoney Keeper
ROSBANK Online
VTB24-Online
MTS Bank
Yandex.Money: online payments
Sberbank Onl@n PJSC SBERBANK
Privat24
Russian Standard mobile bank
UBANK - financial supermarket
Idea Bank
IKO
Bank SMS
OTP Smart
VTB Online (Ukraine)
Oschad 24/7
Platinum Bank
UniCredit Mobile
Raiffeisenbank Online
Ukrgasbank
StarMobile
Chase Mobile
Bank of America Mobile Banking
Wells Fargo Mobile
TD International
TD Spread Trading
Akbank Direkt
Yapı Kredi Mobil Bankacılık
ÇEKSOR
JSC İŞBANK
İşCep
İşTablet
The compromised data is then sent to the C&C servers, where the attackers can access the stolen data. This gives cyber criminals the capability to oversee all the information being collected so they can pick and choose what they want to take advantage of and also control the malicious application on the unsuspecting victim’s device.
Hash:
MD5: beee6b598d006a6f6fc93f6b8764715f
SHA1: 27806e7f4a4a5e3236d52e432e982915ce636da4
SHA256: 7927146c3db630d5a75dca2d97c26e2406f1183df50fdc29d7f40f8ad667ab0
Remediation steps
Last edited: 17 February 2020 11:25 am