According to CSIRT, the malicious software called “Xenomorph” has targeted apps of 56 financial institutions in Europe because of its high impact and high vulnerability rate. Records of Xenomorph’s targeted attacks toll at 28 in Spain, 12 in Italy, 9 in Belgium, and 7 in Portugal, including Cryptocurrency wallets and general-purpose applications such as email services.
Malware alert: NCC alert Nigerians of bank-details stealing app
The Computer Security Incident Response Team (CSIRT) of the NCC has discovered new-fashioned malicious software capable of lifting users’ banking app login details on Android devices.
Recommended articles
The primary purpose of this malware is to steal financial credentials and to intercept SMS and Notification messages in order to sign in and use potential two-factor authentication tokens by overlapping fake login pages on top of legitimate ones, enabling hackers to bypass “SMS-based two-factor authentication” and access ‘victims’ accounts without alerting them.
In a statement, NCC said,
“Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called ‘Fast Cleaner’ ostensibly meant to clear junk, increase device speed and optimize the battery.”
“In reality, this app is only a means by which the Xenomorph Trojan could be propagated easily and efficiently. To avoid early detection or being denied access to the PlayStore, ‘Fast Cleaner’ was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.”
“Once up and running on a victim’s device, Xenomorph can harvest device information and Short Messaging Service, intercept notifications and new SMS messages, perform overlay attacks, and prevent users from uninstalling it. The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.”
As per CSIRT’s report, Fast Cleaner gained over 50,000 downloads despite being removed from Google Play Store.
JOIN OUR PULSE COMMUNITY!
Eyewitness? Submit your stories now via social or:
Email: eyewitness@pulse.ng