Daily Flux Report

Newl Android Malware, DroidBot, Targets 70+ Apps - TechNadu

By Novak Bozovic

Newl Android Malware, DroidBot, Targets 70+ Apps - TechNadu

The malware can intercept SMS messages, log information, and access devices remotely.

Being a fairly open mobile platform, Android is often affected by data-stealing malware and remote access Trojans. Even though Google is focused on increasing the platform's resilience, new malware breeds appear more often than ever. The latest malware breed was discovered by Cleafy researchers, targeting banking and crypto apps.

Named DroidBot, this Remote Access Trojan (RAT) operates as a malware-as-a-service (MaaS). It's available for $3,000 per month, offering less experienced malicious actors the complete set of tools to steal highly sensitive information. This includes the malware builder, command-and-control (C2) servers, and a central admin panel to control operations, extract stolen data, and issue commands.

DroidBot uses standard decoys to trick users into installing fake apps, which usually present as Google services, generic security apps, or popular banking apps. It takes advantage of Android's Accessibility Services to perform its functions. That means the user must willingly provide access to these services, usually during the initial installation stages.

Upon granting access to Accessibility Services, DroidBot can perform a wide range of functionalities, including:

Regarding the affected apps, Cleafy notes that 77 banking and crypto apps have been identified as potential targets. Those include Binance, KuCoin, BBVA, Unicredit, Santander, Metamask, BNP Paribas, Credit Agricole, Kraken, Garanti BBVA, and more.

Furthermore, 17 affiliate groups have been identified, revealing a network of botnets and 770+ infections throughout France, Belgium, Spain, Italy, and Turkey, which are the most targeted countries. Infections were also observed in the UK, Norway, Sweden, Finland, Germany, Poland, Greece, and other European countries.

To avoid a DroidBot infection, Android users are advised to download apps only from the Play Store. They should also scrutinize permission requests and make sure "Play Protect" is active on their mobile devices.

Previous articleNext article

POPULAR CATEGORY

corporate

4625

tech

4993

entertainment

5679

research

2573

misc

5869

wellness

4462

athletics

5990