Author

Topic: Android malware targets 13 bitcoin wallets and 400 banks (Read 251 times)

legendary
Activity: 2716
Merit: 1855
Rollbit.com | #1 Solana Casino
Google is known for their lethargic approach towards the malicious apps available in their playstore, they only remove it when they get so much reports from the users by that time the goal of the malicious apps will be achieved that is why never trust play protect or IOS app market and also the software platforms need to find something to eradicate the malicious apps linked with fabricated apps as soon as possible.

Using Linux is highly recommended for crypto community but it's not user friendly which is the main reason they are going after Android or IOS.
This incident will certainly provide a strong warning to Google so that they are more selective and stricter in releasing several new or existing applications so that this kind of dangerous incident does not occur.

This powerful malware phenomenon makes all security companies overhaul their products in order to fight the sophistication of the methods used by the Xenomorhp V3 malware.

Android users are indeed very vulnerable because they are the main target of the Xenomorph malware, but it is not impossible that all OS will be attacked.

Linux OS users are still small, and not as popular as other OSes. It is not friendly to new users and uses several commands that must be memorized to be able to access it. Although now it has been adjusted and there is a Linux GNOME version that makes it easier for users to be able to access applications on Linux.

Currently, the highest OS usage is still dominated by Android and secondly iOS.


https://www.statista.com/statistics/272698/global-market-share-held-by-mobile-operating-systems-since-2009/




hero member
Activity: 2366
Merit: 793
Bitcoin = Financial freedom
Google is known for their lethargic approach towards the malicious apps available in their playstore, they only remove it when they get so much reports from the users by that time the goal of the malicious apps will be achieved that is why never trust play protect or IOS app market and also the software platforms need to find something to eradicate the malicious apps linked with fabricated apps as soon as possible.

Using Linux is highly recommended for crypto community but it's not user friendly which is the main reason they are going after Android or IOS.
member
Activity: 966
Merit: 25
Ton Together | Save Smart & Win Big
In my opinion, it has become scarier now in the digital world due to the increasing sophistication and prevalence of cyber threats such as malware, ransomware, phishing, and data breaches. These threats not only target individuals but also businesses, organizations, and even governments. The consequences of these attacks can be devastating, ranging from financial loss to reputation damage and even personal harm.

If you suspect that your device may have been infected with the Xenomorph malware or any other type of malware, it is important to take action immediately. Here are some steps you can take:
1. Disconnect your device from the internet: This will prevent the malware from communicating with its command and control server, which could further compromise your device and data.
2. Run a full system scan: Use a reputable antivirus software to scan your device for malware and follow its instructions for removal.
3. Change your passwords: If you suspect that your passwords may have been compromised, change them immediately and consider using a password manager to create strong and unique passwords.
4. Enable two-factor authentication: This can add an extra layer of security to your accounts and help prevent unauthorized access.
5. Keep your software up-to-date: Make sure that your operating system, antivirus software, and other programs are updated with the latest security patches.
6. Be cautious of downloads and links: Avoid downloading files or clicking on links from unknown or suspicious sources.
7. Back up your data: Regularly back up your important files and data to an external hard drive or cloud storage service.

Remember, prevention is always better than cure when it comes to cyber threats. By following good cybersecurity practices and being vigilant about suspicious activity, you can help protect yourself and your data from malware like Xenomorph.
hero member
Activity: 3136
Merit: 591
Leading Crypto Sports Betting & Casino Platform
SMS and 2 Factor Authentication can also be penetrated, which will be very dangerous.
Many lay people only use smartphones and don't pay attention to what applications are downloaded, and sometimes when visiting some websites or installing game applications, there will be advertisements that download applications automatically, this is very dangerous.
This is too worrying for those typical users that don't check the apps downloaded on their smartphones. Since the number of users has been enormous for these smartphones, they're not just targeting PC users but also everybody through this. That's why for websites whether I access them through a PC or a smartphone, whenever there's some unusual activity as per loading, I close it immediately before it performs a task to download automatically or directs me to that.

I am also an android user and start to be wary when I get news like this. Tried checking some apps and uninstalling useless apps.
Thanks for all the heads up including OP, it's concerning and also made me check if I've got some unknown app that I have downloaded just because of being reckless.
legendary
Activity: 2114
Merit: 2248
Playgram - The Telegram Casino
It was so irritating that I got rid of the mobile ad blocker as I would rather have the ads all over the webpage than experiencing much slowed loading times.
If it wasn't uBlock origin that you installed then I would recommend you use it. I've bee using it for months now and have not experienced any lagging when loading a website.
The risk with pop up ads is no matter how careful you are, you can inadvertently click on them, especially when on your mobile device.
legendary
Activity: 2618
Merit: 1181
This is an important warning to anyone, so the advice that really needs to be heed is "do not store your assets on your android or anything connected to the Internet". Even though this is said over and over again, it seems that many people still ignore the warnings. Damn, the rise of the digital industry is also worth the risk.

I never even install any game or app from play store in one last year, it's a precaution that should be considered wisely because some important data still stored in android like personal documents.
legendary
Activity: 2730
Merit: 7065
It is not only a matter of safety, but also that working on such devices is problematic, and the battery wears out quickly.
I remember installing a popular ad blocker on my phone a few months ago because a couple of sites I regularly visited show too many ads on the page which irritated me. The ad blocker worked in the sense that those ads disappeared, but the overall performance of the phone slowed down noticeably. Every time I visited a new website, there was this moment when the phone froze, then it slowly got back to normal loading. It was so irritating that I got rid of the mobile ad blocker as I would rather have the ads all over the webpage than experiencing much slowed loading times.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
Sadly, that tendency of theirs can easily bite them in the ass, and when that happens, they are going to put the blame on everybody and everything except themselves.   

Unfortunately, it's always like that, because everyone thinks that something bad won't happen to them until it does. Today's smartphones are much more than just phones, and most young people try out various apps out of pure curiosity, and it's not that I once cleaned such apps from someone's smartphone that simply slowed down and started freezing because countless apps were running in the background.

It is not only a matter of safety, but also that working on such devices is problematic, and the battery wears out quickly.
legendary
Activity: 2730
Merit: 7065
Be aware that downloading applications from unofficial websites carries huge risks, as they might already have been tampered with by scammers.
Downloading them from official websites like Google's Play Store also carries huge risks because Google does very little to battle and check what their service hosts and advertises. Several apps I have used related to work were unofficial creations developed and shared outside of the Play Store and there are no problems with those. An app downloaded from an app store doesn't mean it's safe, and one downloaded elsewhere from the internet isn't necessarily bad.

After the switch to EUR, many people in my country started using such apps, especially older ones who find it difficult to calculate how much something costs in EUR compared to the old currency. Of course, such things can always be checked online, but most people still have a tendency to use apps for almost every activity we can imagine.
Sadly, that tendency of theirs can easily bite them in the ass, and when that happens, they are going to put the blame on everybody and everything except themselves.   
hero member
Activity: 2408
Merit: 584
Be aware that downloading applications from unofficial websites carries huge risks, as they might already have been tampered with by scammers. I don't see any need to download any other applications on my phone, apart from the browser and wallet app. If you are looking for new applications make sure they have been around for a while and the reviews are good enough too.
Apps coming from unknown sources are a threat, everyone knows that even your mobile warns you of that before installing, but what if the malware is installed from a trusted source such as the Google Play Store as mentioned in the opening post? That could be a serious threat for almost everyone who even doesn't install apps from outside Google Play Store on their android.

People will need to avoid installing unnecessary or even unknown applications even from trusted sources since no one can really know under what kind of apps they hide the malware, and it is too risky.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
~snip~
This malware spreads through a currency converter app. Why would you need to have that installed on your phone? You can literally enter USD to EUR or any other currency pair and get rates from Google.

After the switch to EUR, many people in my country started using such apps, especially older ones who find it difficult to calculate how much something costs in EUR compared to the old currency. Of course, such things can always be checked online, but most people still have a tendency to use apps for almost every activity we can imagine. Therefore, if you download a lot of apps, there is a chance that at least one of them will be malicious, and one is quite enough to cause damage.
sr. member
Activity: 686
Merit: 403
Be aware that downloading applications from unofficial websites carries huge risks, as they might already have been tampered with by scammers. I don't see any need to download any other applications on my phone, apart from the browser and wallet app. If you are looking for new applications make sure they have been around for a while and the reviews are good enough too.
legendary
Activity: 2716
Merit: 1855
Rollbit.com | #1 Solana Casino
-snip-
Some people sometimes just want to test some new applications that they think will make it easier to search. and some foreign applications are sometimes installed themselves because of advertisements from other applications such as in-game applications, tool applications or social media that embed advertisements in them.

Some new app testers are indeed very vulnerable because we also don't know how safe the app is, even users also register their devices to be able to receive Beta Tester apps that are still not even released to the public and only those who register can get the app. This will indeed invite higher risks, if the device is the main device used to install wallets and some other important applications.

-snip-
As an option to avoid such troubles, the use of Linux systems again arises. As far as I know, these two software programs apply to Android and Windows. Although, of course, phone users need to be very careful with the installation of different programs. Since, according to the data, even the Play Market cannot guarantee the safety of users by allowing masquerading programs into their service.
The use of Linux Operating system is not popular among beginners, only those who understand how to operate Linux are interested in using it.
Even in smartphones that are quite vulnerable, Android, and iOS users' cases are still quite rare, but there is also a possibility of being infected if there is another update for the iOS OS.

-snip-
It's not enough to keep your crypto holdings in a separate device, which is a good step, but we still use our mobile for certain things, some use it to open the forum and one cannot access bank applications without internet connection, so the risk still presents itself.
I only use one phone and it is also used to install my personal wallet (but not my main wallet). I am now more selective and do not install strange applications, only common and trusted applications that I install. Always monitoring and scanning applications would be better, so that no suspicious applications are installed on the smartphone I use.
legendary
Activity: 2114
Merit: 2248
Playgram - The Telegram Casino
I am also an android user and start to be wary when I get news like this. Tried checking some apps and uninstalling useless apps.
It's best to not keep apps you don't use, and possibly vet the ones you do use to determine how useful they are and how much risk they lose to you.

It's not enough to keep your crypto holdings in a separate device, which is a good step, but we still use our mobile for certain things, some use it to open the forum and one cannot access bank applications without internet connection, so the risk still presents itself.
legendary
Activity: 2072
Merit: 4265
✿♥‿♥✿
I think it is also worth paying attention to the fact that the Zombinder application itself carries a big threat. According to the data, this software "allows attackers to associate malware with legitimate Android applications, forcing victims to infect themselves, while maintaining the full functionality of the original application to avoid suspicion."

Quote
An interesting aspect of the campaign is the darknet service, which the researchers dubbed “Zombinder,” which offers malicious APK binding of malware to legitimate Android applications.

Zombinder launched in March 2022 as a malware packer on APK files, and according to ThreatFabric, it is now growing popular in the cybercrime community.

The APKs used in this campaign vary, with the analysts reporting seeing a fake live football streaming app and a modified version of the Instagram app.

These apps work as expected because the functionality of the legitimate software is not removed. Instead, Zombinder appends a malware loader to its code.

The loader is obfuscated to evade detection, so when the user launches the app, the loader will display a prompt to install a plugin. If the prompt is accepted, the loader will install a malicious payload and launch it in the background.
https://impreza.host/new-zombinder-platform-binds-android-malware-with-legitimate-apps/

As an option to avoid such troubles, the use of Linux systems again arises. As far as I know, these two software programs apply to Android and Windows. Although, of course, phone users need to be very careful with the installation of different programs. Since, according to the data, even the Play Market cannot guarantee the safety of users by allowing masquerading programs into their service.
legendary
Activity: 2730
Merit: 7065
Scary stuff. I don't remember hearing about this type of malware before, and I as sure as hell don't want to come across it.

I have always guided myself by not being overcurious in installing apps that aren't essential. That has never failed me yet. People have become so lazy and want dedicated apps for every little thing they use in their life. This malware spreads through a currency converter app. Why would you need to have that installed on your phone? You can literally enter USD to EUR or any other currency pair and get rates from Google. If you want even more precision, use something like xe.com. Or check the rates at the website of your bank.

I was having coffee with a friend at a bar recently. And as we were sitting there, the guy was browsing the Play Store and selecting apps he thought looked interesting. I asked him what he was looking for and he said nothing special, I just feel like testing some new apps. That's just inviting problems in your life.
legendary
Activity: 2716
Merit: 1855
Rollbit.com | #1 Solana Casino
WTF, Malware this time is more sophisticated and unstoppable, makes updates that are more specific and can attack any security. I even heard about this Xenomorph Malware, But the first Xenomorph Malware was detected a year ago in February 2022 and has recently undergone a more advanced update with full features.

https://www.bleepingcomputer.com/news/security/new-xenomorph-android-malware-targets-customers-of-56-banks/

Feeling that nothing is safe anymore, when it's the same class as Google Playstore, with Google Play Protect, you can be tricked and infiltrated as a popular application that is widely used and in which malware is injected. Somehow the criteria that Google Play Protect has so that applications injected with Xenomorph Malware can escape.

Even popular applications such as Cleaner and Fast for android phones, Keyboard applications and the like, are the most downloaded in the hope of being cleaner than Malware but instead, they fall into a trap.

SMS and 2 Factor Authentication can also be penetrated, which will be very dangerous.
Many lay people only use smartphones and don't pay attention to what applications are downloaded, and sometimes when visiting some websites or installing game applications, there will be advertisements that download applications automatically, this is very dangerous.


Extracting one-time codes from Google Authenticator (ThreatFabric)


Process of stealing cookies (ThreatFabric)


Hadoken Security Group claimed ownership of Xenomorph Malware in May 2022


Using a Discord Content Delivery Network (CDN) hosting service, it is not uncommon for malware authors to use services such as Discord CDN or GitHub repositories to hide their products invisibly.

All security or Anti Virus companies seem to have to immediately update their Database so that not many victims suffer losses due to this Xenomorph V3 Malware.

I am also an android user and start to be wary when I get news like this. Tried checking some apps and uninstalling useless apps.
legendary
Activity: 2072
Merit: 4265
✿♥‿♥✿
New article on Xenomorph malware.
https://twitter.com/ThreatFabric/status/1634131991216914432?cxt=HHwWgICwyeqYza0tAAAA


The Xenomorph v3 version is much more powerful than the previous ones that were previously discovered.
The software targeted several banks Chase, Citibank, American Express, ING, HSBC, Deutsche Bank, Wells Fargo and other banks from around the world, as well as crypto wallets: Binance, BitPay, KuCoin, Gemini and Coinbase.
"Xenomorph v3 is currently being distributed via the Zombinder platform on the Google Play Store, posing as a currency converter and switching to using the Play Protect icon after installing a malicious payload."

Quote
ThreatFabric has included a list of all targeted banks in the appendix of its report, but it would be too long to present here. In addition, 13 cryptocurrency wallets, including Binance, BitPay, KuCoin, Gemini, and Coinbase, are targeted by malware.

The most noticeable addition to the latest Xenomorph version is the ATS framework, which gives hackers the ability to automatically extract credentials, monitor account balances, make transactions, and steal money from target apps without requiring them to perform remote activities.

Instead, the operator merely sends JSON scripts, which the Xenomorph interprets as a list of activities and then carries out on the infected device on its own.

According to experts at ThreatFabrics, the [ATS execution] engine utilized by Xenomorph differs from its rivals due to the range of programmable potential actions that can be included in ATS scripts and a system that permits conditional execution and action prioritization.

One of the malware’s ATS framework’s most outstanding features is its ability to record third-party authentication programs’ content, circumventing MFA (multi-factor authentication) safeguards that would otherwise prevent automated transactions.

One-time codes can be obtained from Google Authenticator by extracting the relevant codes (ThreatFabric). It concerns that Xenomorph may access authenticator applications on the same device as banks, who are gradually moving away from SMS MFA and advising consumers to use authenticator apps instead.

In addition to the aforementioned, the new Xenomorph has a cookie stealer capable of stealing cookies from the Android CookieManager, where the user’s session cookies are kept.

In order to fool the victim into providing their login information, the thief launches a browser window with the URL of a reliable service and the JavaScript interface turned on.

The threat actors steal the cookies, allowing them to hijack the victim’s web sessions and access their accounts. A significant new malware that entered the world of cybercrime a year ago was Xenomorph, an Android threat.

It is now a far bigger threat to Android users all over the world after the release of its third major version. Users who download apps via Google Play should exercise caution, read reviews, and perform background checks on the publisher because of the app’s current distribution method, the Zombinder.

https://informationsecuritybuzz.com/xenomorph-android-malware-steals-banks/
Jump to: