Android banking malware exploits weaknesses to perform info-stealing operations: Report 

The Hindu Bureau The Hindu Bureau | 04-19 00:10

A new Android banking malware was found exploiting weaknesses in the Android manifest extraction and parsing procedure to perform information stealing operations. The malware is reported to be capable of evading standard security measures found in Android, making use of Android routine to parse and extract APK manifests, which is used to define the structure and store the Metadata of an application.

The malware was found to be capable of stealing user information including IP addresses, contact lists, account details, SMS messages, photos, videos, and online banking digital certificates. This exfiltration by the malware was found to be controlled remotely via a server, and could also receive commands to perform malicious activities. These include deleting existing or adding contacts, sending an SMS message, setting ringtone volume levels, and turning the debug mode on and off on a device.

While the method of infection of devices is unclear, researchers suggest that the malware may be rechecking devices over third-party Android stores and unsafe websites. Researchers also suggest that the malware may be spread through updates for apps with malicious code in legitimate apps.

The malware was first detected and analysed by Kaspersky researchers, who found that the malware can use malicious APKs to fool security tools and evade analysis. Researchers further reported that the malware uses three different approaches that involve manipulation of the manifest file’s compression and size, to bypass checks in the Android operating system.

(For top technology news of the day, subscribe to our tech newsletter Today’s Cache)

Like many malicious Android apps, the malware hides its icon upon installation in a device, making it more difficult to remove and detect. However, it remains active in the background, sharing the stolen data with threat actors.

Disclaimer: The copyright of this article belongs to the original author. Reposting this article is solely for the purpose of information dissemination and does not constitute any investment advice. If there is any infringement, please contact us immediately. We will make corrections or deletions as necessary. Thank you.


ALSO READ

Ola Electric responds to ARAI notice, says prices of S1 X 2 kWh scooter unchanged

Ola Electric provided an invoice dated October 6, showing a INR 5,000 discount given to customers, a...

Hyundai Motor IPO’s off to a slow start

Around 35% of the total shares in the offering are reserved for retail investors, while QIBs and NII...

Under fire, Ola Electric taps EY India to get back on track

Close to a dozen executives from EY came on-board at Ola Electric a few weeks ago on deputation for ...

Tata Motors secures 5-star BNCAP safety ratings for Nexon, Curvv, and EV models in latest crash tests

Tata Curvv.EV BNCAP testTata Motors did it again! Tata Motors has once again secured 5 star rating i...

India needs to step up manufacturing to meet Viksit Bharat goal: Volvo Grp India MD

Volvo Group India Managing Director and President, Kamal Bali. The manufacturing sector is a weak li...

Dollar pullback to help Indian rupee, weak risk appetite to weigh

Investors are now nearly certain that the U.S. Federal Reserve will deliver a 25-basis-point rate cu...