Skip to main content

Android banking malware source code published

The source code of a new Android banking malware has been published along with instructions on how to use it.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

The source code of a new Android banking malware has been published along with instructions on how to use it.

Affected platforms

The following platforms are known to be affected:

Threat details

Security researchers believe that this particular code has the potential to cause a spike in the number of attacks involving Android banking Trojans. Attackers may take advantage of the malicious code to attack banks around the globe. Currently, this particular variant has been found targeting only users of Russian banks.

The new malware is distributed under the guise of benign programs for example, Google programs with the Play Store icon. Once the device user installs and runs Bankbot, it prompts the user to grant it administrator privileges to thwart its removal from the system. Once obtained, the Trojan removes the app's icon from the phone's home screen in order to trick victims into believing it was removed. However, it will still remain active in the background, waiting for commands from attacker's command and control (C&C) server. BankBot has the ability to perform a broad range of tasks, including send and intercept SMS messages, make calls, track devices, steal contacts, show phishing dialogs and steal sensitive information, like banking and credit card details.

Bankbot has the ability to conceal itself until the victim opens up a targeted mobile banking or social media app. Once opened, the malware launches a phishing login overlay, which allows the Trojan to store user credentials as it displays the information on top of the attacked application. Bankbot will then prompt victims to re-authenticate or re-enter their payment card details. The Trojan not only steals mobile banking login credentials but also bank card information belonging to the owner of the compromised device which is why it tracks the launch of certain apps so it can phish credentials. The apps being targeted include Facebook, WhatsApp, Instagram, Twitter, YouTube, Snapchat, Viber, WeChat, imo, Uber and the Google Play Store.

In addition, the BankBot Trojan can also intercept text messages, send them to the attackers and then delete them from the victim's smartphone, which means bank notifications never reach the users.

Bankbot scans smartphones and tablets for the presence of the following banking applications and payment systems:

Sberbank Online
Sberbank Business Online
Alfa-Bank
Alfa-Business
Visa QIWI Wallet
R-Connect mobile bank
Tinkoff
PayPal
WebMoney Keeper
ROSBANK Online
VTB24-Online
MTS Bank
Yandex.Money: online payments
Sberbank Onl@n PJSC SBERBANK
Privat24
Russian Standard mobile bank
UBANK - financial supermarket
Idea Bank
IKO
Bank SMS
OTP Smart
VTB Online (Ukraine)
Oschad 24/7
Platinum Bank
UniCredit Mobile
Raiffeisenbank Online
Ukrgasbank
StarMobile
Chase Mobile
Bank of America Mobile Banking
Wells Fargo Mobile
TD International
TD Spread Trading
Akbank Direkt
Yapı Kredi Mobil Bankacılık
ÇEKSOR
JSC İŞBANK
İşCep
İşTablet

The compromised data is then sent to the C&C servers, where the attackers can access the stolen data. This gives cyber criminals the capability to oversee all the information being collected so they can pick and choose what they want to take advantage of and also control the malicious application on the unsuspecting victim’s device.

Hash:
MD5: beee6b598d006a6f6fc93f6b8764715f
SHA1: 27806e7f4a4a5e3236d52e432e982915ce636da4
SHA256: 7927146c3db630d5a75dca2d97c26e2406f1183df50fdc29d7f40f8ad667ab0


Remediation steps

Type Step
Enterprises are advised to scan their networks using the IOC’s to identify, detect and protect networks from the malware.
Consumers are advised to run full system scan using AV software and follow recommendations to neutralise the detected threats.
Be extra cautious when downloading APKs from third-party app stores. Consider restricting the ability to install apps from sources other than from official stores.
Do not open attachments from unknown or suspicious sources.

Last edited: 17 February 2020 11:25 am