New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Fake Antivirus Apps on Play Store Loaded with SharkBot Banking Trojan

New York Tech Editorial Team by New York Tech Editorial Team
March 7, 2022
in Cybersecurity
0
Fake Antivirus Apps on Play Store Loaded with SharkBot Banking Trojan
Share on FacebookShare on Twitter

The SharkBot trojan was found in four fake antivirus apps on Google Play Store collectively boasting 57,000 downloads.

British IT security researchers from NCC Group have discovered an updated version of the malicious SharkBot banking trojan hidden inside an antivirus app available on the Google Play Store.

Malicious Apps Hiding SharkBot Malware

SharkBot’s new version is hidden inside a fake antivirus app, which functions as a 3-layer poison pill. The first layer masquerades as an antivirus while the second layer extracts a scaled-down SharkBot version.

The malware then downloads its newest version boasting a wide range of capabilities. Researchers spotted the latest version of SharkBot on February 28th, 2022.

Numerous Play Store Apps Leveraging the Malware

NCC Group researchers further noted that several other dropper apps also leverage Android’s Direct Reply function to infect other devices. Hence, after FluBot, SharkBot is the second banking trojan that can intercept notifications for wormable attacks.

The researcher also published the list of malicious apps, collectively boasting 57,000 downloads. The apps include:

  1. Antivirus Super Cleaner (1000+ installs).
  2. Alpha Antivirus Cleaner (5,000+ installs).
  3. Atom Clean-Booster antivirus (500+ installs).
  4. Powerful Cleaner antivirus (50,000+ installs).

About SharkBot Malware

SharkBot is a remote access banking trojan first discovered in the wild in October-November 2021 by security researchers at Cleafy. At that time, researchers concluded that the malware was unique and had no similarities or connection with other malware like Xenomorph or TeaBot.

They further explained that SharkBot was a highly sophisticated malware. Like its counterparts, e.g. FluBot, TeaBot, and Oscorp/UBEL, it is a financial trojan that can siphon credentials to transfer money from compromised devices. To perform the transfer, SharkBot circumvents MFA mechanisms.

SharkBot Unique Capabilities

What makes SharkBot stand out is the Automatic Transfer System or ATS. This unique system allows attackers to automatically move money from the victim’s account without any human intervention.

SharkBot can also carry out unauthorized transactions easily through the ATS mechanism. This is what makes it different from TeaBot as it requires input from a live operator to conduct malicious activities on the infected devices.

NCC Group’s malware analysts Alberto Segura and Rolf Govers explained the ATS feature in their report published last week:

The ATS features allow the malware to receive a list of events to be simulated, and they will be simulated in order to do the money transfers. Since these features can be used to simulate touches/clicks and button presses, it can be used to not only automatically transfer money but also install other malicious applications or components.


Alberto Segura

This means ATS is used to deceive a bank’s fraud detection system by creating a similar action sequence a user may otherwise perform to make the transaction, such as clicks or button presses.

More Play Store Malware News

  1. Squid Game app on Play Store was spreading Joker malware
  2. New malware “BlackRock” disguised as Android Clubhouse app
  3. 300,000 Android users impacted by malware apps on Play Store
  4. Fake Netflix app on Play Store caught hijacking WhatsApp sessions
  5. Hacked Android phones mimicked connected TV products for fake ad views

SharkBot- A Feature-Rich Malware

NCC Group’s cybersecurity researchers claim that SharkBot is an immensely feature-rich malware. It allows an attacker to inject fake overlays on official banking apps to obtain complete remote control of the infected device(s), log keystrokes, and steal credentials.

However, it will gain control of a device if the victim grants it Accessibility Services permission. The malware performs an overlay attack as soon as it detects an active banking app. It displays a screen similar to the app and asks for the user’s credentials while secretly activating a keylogger. Whatever the user type is sent to the attacker’s server.

Furthermore, the malware can intercept and hide SMS messages, hijack incoming notifications, and send out messages originating with the attackers’ C2 server. Through these tactics, it can gain full control of an Android smartphone.

Credit: Source link

Previous Post

Build your pitch deck around problem-solving, not technology – TechCrunch

Next Post

Invata Rolls Out New Line of Mobile Robotics

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Invata Rolls Out New Line of Mobile Robotics

Invata Rolls Out New Line of Mobile Robotics

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
Coffee Nova’s $COFFEE Token

Coffee Nova’s $COFFEE Token

May 29, 2025
Money TLV website

BridgerPay to Spotlight Cross-Border Payments Innovation at Money TLV 2025

May 27, 2025
The Future of Software Development: Why Low-Code Is Here to Stay

Building Brand Loyalty Starts With Your Team

May 23, 2025
Tork Media Expands Digital Reach with Acquisition of NewsBlaze and Buzzworthy

Creative Swag Ideas for Hackathons & Launch Parties

May 23, 2025
Tork Media Expands Digital Reach with Acquisition of NewsBlaze and Buzzworthy

Strengthening Cloud Security With Automation

May 22, 2025
How Local IT Services in Anderson Can Boost Your Business Efficiency

Why VPNs Are a Must for Entrepreneurs in Asia

May 22, 2025

Recommended

Coffee Nova’s $COFFEE Token

Coffee Nova’s $COFFEE Token

May 29, 2025
Money TLV website

BridgerPay to Spotlight Cross-Border Payments Innovation at Money TLV 2025

May 27, 2025
The Future of Software Development: Why Low-Code Is Here to Stay

Building Brand Loyalty Starts With Your Team

May 23, 2025
Tork Media Expands Digital Reach with Acquisition of NewsBlaze and Buzzworthy

Creative Swag Ideas for Hackathons & Launch Parties

May 23, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech crypto cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media