Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

New Android malware straddles the line between banking Trojan and spyware

Altszn.com by Altszn.com
January 24, 2023
in Dark Web
0
New Android malware straddles the line between banking Trojan and spyware
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


New Android malware straddles the line between banking Trojan and spyware

Security researchers have uncovered a disturbing new piece of Android banking malware with some very expanded capabilities.

The new malware, called Hook, was thought to be a fork of the Ermac malware, which was itself based on the well-known malware Cerberus. However, researchers at fraud specialist ThreatFabric found that while it was largely based on much the same code as Ermac, its creator had added some very advanced spyware features.

Hook, like Ermac before it, is currently being advertised for sale on the dark web by a hacker known as DukeEugene. 

The malware communicates with its command and control servers via HTTP traffic, and WebSocket, which is a new addition to this variant. C2 servers can be set to command the malware to use one or the other to communicate once the malware has been successfully installed on a device.

Hook can target a vast number of banking institutions out of the box from all over the world. The United States and Spain are the top two targets, but Australia is not far behind, with 56 banking institutions in the malware’s crosshairs.

The malware can now also target crypto transactions, with eight separate wallets whose seed phrases (a string of words users can use to get back into locked accounts) can be harvested. 

WhatsApp interactions are another new addition. Threat actors can now not only log all messages sent and received but also send messages themselves. According to ThreatFabric’s researchers, this could be a vector for spreading the malware to other users. Hook can also retrieve lists of files and then download them to a remote server. 

But it is the remote takeover functionality by way of a device’s accessibility services that is a truly scary addition. 

ISCOVER

The new malware can now simulate clicks, keypresses, and gestures; access text boxes; and unlock devices. On top of this, Hook can also geolocate users.

“With this feature, Hook joins the ranks of malware families that are able to perform full DTO, and complete a full fraud chain, from PII exfiltration to transaction, with all the intermediate steps, without the need of additional channels,” ThreatFabric said. 

“This kind of operation is much harder to detect by fraud scoring engines and is the main selling point for Android bankers.”

You can find a full list of the malware’s capabilities and banking targets here.

David Hollingworth

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

New Android malware straddles the line between banking Trojan and spyware

open-banking-ne.jpg

cybersecurity logo

Last Updated: 24 January 2023

Published: 24 January 2023



Read More: news.google.com

Tags: Androidbankingdark webDarknetlineMalwareSpywareStraddlesTrojan
ADVERTISEMENT

Recent

AI scammers are now impersonating US government bigwigs, says FBI

AI scammers are now impersonating US government bigwigs, says FBI

May 16, 2025
Asset tokenization expected to speed capital flows, says Chainlink’s Nazarov

Asset tokenization expected to speed capital flows, says Chainlink’s Nazarov

May 15, 2025
Cardano Eyes Milestone as Hoskinson Teases Blockchain’s First Privacy Stablecoin

Cardano Eyes Milestone as Hoskinson Teases Blockchain’s First Privacy Stablecoin

May 15, 2025

Categories

  • Bitcoin (4,836)
  • Blockchain (11,372)
  • Crypto (9,312)
  • Dark Web (545)
  • DeFi (8,376)
  • Ethereum (4,886)
  • Metaverse (7,490)
  • Monero (288)
  • NFT (1,459)
  • Solana (5,038)
  • Web3 (20,652)
  • Zcash (503)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    AI scammers are now impersonating US government bigwigs, says FBI

    AI scammers are now impersonating US government bigwigs, says FBI

    May 16, 2025
    Asset tokenization expected to speed capital flows, says Chainlink’s Nazarov

    Asset tokenization expected to speed capital flows, says Chainlink’s Nazarov

    May 15, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 103,978.00
    • ethereumEthereum (ETH) $ 2,587.78
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.43
    • bnbBNB (BNB) $ 658.41
    • solanaSolana (SOL) $ 172.92
    • usd-coinUSDC (USDC) $ 0.999806
    • dogecoinDogecoin (DOGE) $ 0.227135
    • cardanoCardano (ADA) $ 0.783557
    • tronTRON (TRX) $ 0.277409
    • staked-etherLido Staked Ether (STETH) $ 2,588.24
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 103,990.00
    • suiSui (SUI) $ 3.89
    • wrapped-stethWrapped stETH (WSTETH) $ 3,104.40
    • chainlinkChainlink (LINK) $ 16.34
    • avalanche-2Avalanche (AVAX) $ 23.96
    • stellarStellar (XLM) $ 0.296904
    • shiba-inuShiba Inu (SHIB) $ 0.000015
    • hyperliquidHyperliquid (HYPE) $ 26.62
    • hedera-hashgraphHedera (HBAR) $ 0.200443
    • leo-tokenLEO Token (LEO) $ 8.85
    • bitcoin-cashBitcoin Cash (BCH) $ 400.39
    • the-open-networkToncoin (TON) $ 3.11
    • litecoinLitecoin (LTC) $ 100.69
    • polkadotPolkadot (DOT) $ 4.87
    • usdsUSDS (USDS) $ 0.999806
    • wethWETH (WETH) $ 2,593.40
    • moneroMonero (XMR) $ 338.99
    • pi-networkPi Network (PI) $ 0.860349
    • wrapped-eethWrapped eETH (WEETH) $ 2,758.82
    • bitget-tokenBitget Token (BGB) $ 5.02
    • pepePepe (PEPE) $ 0.000014
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,029.00
    • whitebitWhiteBIT Coin (WBT) $ 30.30
    • bittensorBittensor (TAO) $ 440.44
    • uniswapUniswap (UNI) $ 6.36
    • daiDai (DAI) $ 0.999985
    • nearNEAR Protocol (NEAR) $ 2.93
    • aaveAave (AAVE) $ 234.54
    • aptosAptos (APT) $ 5.41
    • okbOKB (OKB) $ 53.69
    • ondo-financeOndo (ONDO) $ 0.990009
    • kaspaKaspa (KAS) $ 0.118682
    • jito-staked-solJito Staked SOL (JITOSOL) $ 207.99
    • internet-computerInternet Computer (ICP) $ 5.53
    • ethereum-classicEthereum Classic (ETC) $ 19.27
    • crypto-com-chainCronos (CRO) $ 0.101190
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • bitcoinBitcoin (BTC) $ 103,978.00
    • ethereumEthereum (ETH) $ 2,587.78
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.43
    • bnbBNB (BNB) $ 658.41
    • solanaSolana (SOL) $ 172.92
    • usd-coinUSDC (USDC) $ 0.999806
    • dogecoinDogecoin (DOGE) $ 0.227135
    • cardanoCardano (ADA) $ 0.783557
    • tronTRON (TRX) $ 0.277409
    • staked-etherLido Staked Ether (STETH) $ 2,588.24
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 103,990.00
    • suiSui (SUI) $ 3.89
    • wrapped-stethWrapped stETH (WSTETH) $ 3,104.40
    • chainlinkChainlink (LINK) $ 16.34
    • avalanche-2Avalanche (AVAX) $ 23.96
    • stellarStellar (XLM) $ 0.296904
    • shiba-inuShiba Inu (SHIB) $ 0.000015
    • hyperliquidHyperliquid (HYPE) $ 26.62
    • hedera-hashgraphHedera (HBAR) $ 0.200443
    • leo-tokenLEO Token (LEO) $ 8.85
    • bitcoin-cashBitcoin Cash (BCH) $ 400.39
    • the-open-networkToncoin (TON) $ 3.11
    • litecoinLitecoin (LTC) $ 100.69
    • polkadotPolkadot (DOT) $ 4.87
    • usdsUSDS (USDS) $ 0.999806
    • wethWETH (WETH) $ 2,593.40
    • moneroMonero (XMR) $ 338.99
    • pi-networkPi Network (PI) $ 0.860349
    • wrapped-eethWrapped eETH (WEETH) $ 2,758.82
    • bitget-tokenBitget Token (BGB) $ 5.02
    • pepePepe (PEPE) $ 0.000014
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,029.00
    • whitebitWhiteBIT Coin (WBT) $ 30.30
    • bittensorBittensor (TAO) $ 440.44
    • uniswapUniswap (UNI) $ 6.36
    • daiDai (DAI) $ 0.999985
    • nearNEAR Protocol (NEAR) $ 2.93
    • aaveAave (AAVE) $ 234.54
    • aptosAptos (APT) $ 5.41
    • okbOKB (OKB) $ 53.69
    • ondo-financeOndo (ONDO) $ 0.990009
    • kaspaKaspa (KAS) $ 0.118682
    • jito-staked-solJito Staked SOL (JITOSOL) $ 207.99
    • internet-computerInternet Computer (ICP) $ 5.53
    • ethereum-classicEthereum Classic (ETC) $ 19.27
    • crypto-com-chainCronos (CRO) $ 0.101190
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00