New DroidBot Android malware targets 77 banking, crypto apps

Share:

A new Android banking malware named ‘DroidBot’ attempts to steal credentials for over 77 cryptocurrency exchanges and banking apps in the UK, Italy, France, Spain, and Portugal.

According to Cleafy researchers who discovered the new Android malware, DroidBot has been active since June 2024 and operates as a malware-as-a-service (MaaS) platform, selling the tool for $3,000/month.

At least 17 affiliate groups have been identified using malware builders to customize their payloads for specific targets.

Although DroidBot lacks any novel or sophisticated features, analysis of one of its botnets revealed 776 unique infections across the UK, Italy, France, Turkey, and Germany, indicating a significant activity.

Also, Cleafy says the malware appears to be under heavy development at the time, with signs of attempting expansion to new regions, including Latin America.

The DroidBot MaaS operation

DroidBot’s developers, who appear to be Turkish, provide affiliates with all the tools required to conduct attacks. This includes the malware builder, command and control (C2) servers, and a central administration panel from which they can control their operations, retrieve stolen data, and issue commands.

Creators claiming DroidBot was tested on Android 14
Creators claiming DroidBot works well on Android 14
Source: Cleafy

Multiple affiliates operate on the same C2 infrastructure, with unique identifiers assigned to each group, allowing Cleafy to identify 17 threat groups.

Affiliates extracted from the sample's configuration
Affiliates extracted from the sample’s configuration
Source: Cleafy

The payload builder allows the affiliates to customize DroidBot to target specific applications, use different languages, and set other C2 server addresses.

Affiliates are also provided access to detailed documentation, support from the malware’s creators, and access to a Telegram channel where updates are published regularly.

All in all, the DroidBot MaaS operation makes the barrier of entry fairly low for inexperienced or low-skilled cybercriminals.

Impersonating popular apps

DroidBot is often masqueraded as Google Chrome, Google Play store, or ‘Android Security’ as a way to trick users into installing the malicious app.

However, in all cases, it acts as a trojan attempting to steal sensitive information from apps.

The main features of the malware are:

  • Keylogging – Capturing every keystroke entered by the victim.
  • Overlaying – Displaying fake login pages over legitimate banking app interfaces.
  • SMS interception – Hijacks incoming SMS messages, particularly those containing one-time passwords (OTPs) for banking sign-ins.
  • Virtual Network Computing – VNC module gives affiliates the capability to remotely view and control the infected device, execute commands, and darken the screen to hide the malicious activity.

A key aspect of DroidBot’s operation is the abuse of Android’s Accessibility Services to monitor user actions and simulate swipes and taps on behalf of the malware. Therefore, if you install an app that requests strange permissions, like the Accessibility Services, you should immediately become suspicious and deny the request.

Among the 77 apps DroidBot attempts to steal credentials, some standouts include Binance, KuCoin, BBVA, Unicredit, Santander, Metamask, BNP Paribas, Credit Agricole, Kraken, and Garanti BBVA.

To mitigate this threat, Android users are advised to only download apps from Google Play, scrutinize permission requests upon installation, and make sure Play Protect is active on their devices.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:46 am, Jan 18, 2025
weather icon 2°C
L: 1° | H: 3°
overcast clouds
Humidity: 89 %
Pressure: 1031 mb
Wind: 5 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 7 km
Sunrise: 7:56 am
Sunset: 4:24 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
1° | 3°°C 0 mm 0% 4 mph 90 % 1031 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
1° | 5°°C 0 mm 0% 7 mph 93 % 1024 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
3° | 8°°C 0.26 mm 26% 6 mph 97 % 1019 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 95 % 1019 mb 0 mm/h
Wed Jan 22 9:00 pm
weather icon
4° | 7°°C 1 mm 100% 4 mph 99 % 1012 mb 0 mm/h
Today 9:00 am
weather icon
2° | 2°°C 0 mm 0% 2 mph 89 % 1031 mb 0 mm/h
Today 12:00 pm
weather icon
3° | 5°°C 0 mm 0% 3 mph 83 % 1031 mb 0 mm/h
Today 3:00 pm
weather icon
4° | 6°°C 0 mm 0% 3 mph 75 % 1028 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 3°°C 0 mm 0% 4 mph 88 % 1026 mb 0 mm/h
Today 9:00 pm
weather icon
2° | 2°°C 0 mm 0% 3 mph 90 % 1025 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 2°°C 0 mm 0% 3 mph 89 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
1° | 1°°C 0 mm 0% 3 mph 91 % 1022 mb 0 mm/h
Tomorrow 6:00 am
weather icon
1° | 1°°C 0 mm 0% 3 mph 93 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,326.42
0.93%
Ethereum(ETH)
€3,193.60
-3.42%
XRP(XRP)
€3.04
-4.48%
Tether(USDT)
€0.97
-0.02%
Solana(SOL)
€231.29
10.47%
Dogecoin(DOGE)
€0.387292
-3.87%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000022
-6.11%
Pepe(PEPE)
€0.000019
-4.00%
Peanut the Squirrel(PNUT)
€0.52
-15.32%
Scroll to Top