First SpyEye Attack On Android Spotted In The Wild

  /     /     /  
Publicated : 22/11/2024   Category : security


First SpyEye Attack On Android Spotted In The Wild


Banking Trojan pretends to be an additional security measure offered by the users bank



A new Android Trojan that masquerades as banking security software has been spotted in the wild, researchers say.
The smartphone-targeted attack uses a combination of social engineering and downloadable malware to infect Android devices, according to researchers at F-Secure and a
blog by researchers at Trusteer
.
The Trojan injects fields into the banks webpage and asks the customer to input his mobile phone number and the IMEI of the phone, the Trusteer blog says. The bank customer is then told the information is needed so a certificate can be sent to the phone and is informed that it can take up to three days before the certificate is ready.
The Trojan is signed with a developer certificate, according to F-Secure. Developer certificates are tied to certain IMEIs and can only be installed to phones that have an IMEI that is listed in the certificate. This is why the malware author[s] request the IMEI in addition to the phone number on the banks website. Once they receive new IMEIs, they request an updated certificate with IMEIs for all victims and create a new installer signed with the updated certificate.
The delay in getting the new certificate explains why the SpyEye-injected message states it can take up to three days for the certificate to be delivered, F-Secure says.
But the three-day waiting period occurred mostly in Symbian OS environments, Trusteer observes. The Android OS can be infected much more quickly and efficiently, and the infection can be more readily hidden.
After the compromised user installs the Android application on his/her device, the application named System is not visible on the device dashboard, Trusteer says. Its not a service, and it’s not listed in any current running applications. In order for a user to determine the existence of this app a bit of searching is required.
Some anti-malware software providers, including F-Secure and Trusteer, say they have already implemented changes to their products to protect users against the new threat.
Have a comment on this story? Please click Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
First SpyEye Attack On Android Spotted In The Wild