Another new trojan was discovered recently, dubbed as SOVA - which is a Russian word for "Owl". It stand out from other Android malware/trojan is that it is a session cookie theft. What makes it dangerous is that the criminals can now have access to valid logged in sessions without needing your banking credentials.
Functionalities of the bot, as advertised by its authors, include:
Steal Device Data.
Send SMS.
Overlay and Cookie injection.
Overlay and Cookie injection via Push notification.
USSD execution.
Credit Card overlays with validity check.
Hidden interception for SMS.
Hidden interception for Notifications.
Keylogger.
Uninstallation of the app.
Resilience from uninstallation from victims.
screenshot of VirusTotal:
Clipper & Cryptocurreny wallets
Another feature that is incorporated in S.O.V.A., that we observed in other malware like Medusa, is the ability of altering the data in the system clipboard. The bot sets up an event listener, designed to notify the malware whenever some new data is saved in the clipboard. If the string of data is potentially a cryptocurrency wallet address, S.O.V.A. substitutes it with a valid address for the corresponding cryptocurrency.
The supported cryptocurrencies are Bitcoin, Ethereum, Binance coin, and TRON. The relative addresses can be found in the IOC section.
The good thing though is that no one has fallen victims so far, but who knows, maybe when it goes and scattered in the wild victims are going to come out.
You can read it here:
https://www.threatfabric.com/blogs/sova-new-trojan-with-fowl-intentions.html