Thứ Tư, Tháng Hai 8, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

MaliBot: New Android Banking Trojan Discovered in the Wild

16 Tháng Sáu, 2022
in Tech
0
MaliBot: New Android Banking Trojan Discovered in the Wild
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

Android banking Trojan

A series malware New Android has been discovered targeting wallet customers electronic money and online banking in Spain and Italy, just weeks after a coordinated law enforcement crackdown on FluBot.

Information stealing Trojan, codenamed MaliBot of F5 Labs, has many of the same features as its counterparts, allowing it to steal credentials and cookies, bypass multi-factor authentication (MFA) codes, and abuse Android Accessibility Services for tracking victim’s device screen.

MaliBot is known to mainly disguise itself as cryptocurrency mining apps like Mining X or The CryptoApp that are distributed through phishing websites designed to lure potential visitors to download.

It also takes another leaf out of the mobile banking trojan game in that it uses polishing as a distribution vector to develop malware by accessing the contacts of an infected smartphone and sending SMS messages that contain links to malware.

“Command and control by MaliBot (C2) in Russia and apparently using the same servers that were used to deliver the Sality malware,” said F5 Labs researcher Dor Nizar. “This is a remake of the heavily modified SOVA malware, with different functions, targets, C2 servers, domains, and packaging scheme.”

Android banking Trojan

SOVA (meaning “Owl” in Russian), first discovered in August 2021, is notable for its ability to conduct overlay attacks, which work by displaying a phishing page using a WebView with a link provided by the C2 server if the victim opens a banking application that is on its active target list.

Some of the banks targeted by MaliBot using this approach include UniCredit, Santander, CaixaBank and CartaBCC.

Accessibility service is a background service that runs in Android devices to assist users with disabilities. It has long been used by spyware and trojans to capture device content and intercept credentials entered by unsuspecting users on other apps.

Besides being able to get your account’s password and cookies Google of victims, the malware is designed to scan 2FA codes from the Google Authenticator app as well as filter sensitive information such as total balances and root phrases from the Binance and Trust Wallet apps.

Android banking Trojan

Furthermore, Malibot has the ability to weaponize its access to the Accessibility API to defeat Google’s two-factor authentication (2FA) methods, such as Google’s prompts, even in cases of attempt to log into the account using credentials stolen from a previously unknown device.

“The versatility of the malware and the control it gives attackers on the device means it could, in principle, be used for a wide range of purposes,” the researchers said. attacks rather than stealing credentials and cryptocurrencies,” the researchers said.

“In fact, any application that uses WebView can have user credentials and cookies stolen.”

.

Previous Post

Download Lumion Pro 12 – Detailed installation instructions

Next Post

The most beautiful living room wall alcove decorations in 2022

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
The most beautiful living room wall alcove decorations in 2022

The most beautiful living room wall alcove decorations in 2022

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem