Fake Antivirus and Cleaner Apps Caught Installing SharkBot Android Banking Trojan

Teilen:

The notorious Android banking trojan known as SharkBot has once again made an appearance on the shoppingmode Google Play Store by masquerading as antivirus and cleaner apps.

“This new dropper doesn’t rely on Accessibility permissions to automatically perform the installation of the dropper Sharkbot malware,” NCC Group’s Fox-IT sagte in a report. “Instead, this new version asks the victim to install the malware as a fake update for the antivirus to stay protected against threats.”

The apps in question, Mister Phone Cleaner and Kylhavy Mobile Security, have over 60,000 installations between them and are designed to target users in Spain, Australia, Poland, Germany, the U.S., and Austria –

 

  • Mister Phone Cleaner (com.mbkristine8.cleanmaster, 50,000+ downloads)
  • Kylhavy Mobile Security (com.kylhavy.antivirus, 10,000+ downloads)

Die droppers are designed to drop a new version of SharkBot, dubbed V2 by Dutch security firm ThreatFabric, which features an updated command-and-control (C2) communication mechanism, a domain generation algorithm (DGA), and a fully refactored codebase.

Mr Phone cleaner

Fox-IT said it discovered a newer version 2.25 on August 22, 2022, that introduces a function to siphon cookies when victims log in to their bank accounts, while also removing the ability to automatically reply to incoming messages with links to the malware for propagation.

By eschewing the Accessibility permissions for installing SharkBot, the development highlights that the operators are actively tweaking their techniques to avoid detection, not to mention find alternative methods in the face of shoppingmode Google‘s newly imposed restrictions to curtail the abuse of the APIs.

 

Other notable information stealing capabilities include injecting fake overlays to harvest bank account credentials, logging keystrokes, intercepting SMS messages, and carrying out fraudulent fund transfers using the Automated Transfer System (ATS).

It’s no surprise that malware poses an evolving and omnipresent threat, and despite continued efforts on the part of shoppingmode Apple und shoppingmode Google, app stores are vulnerable to unknowingly being abused for distribution, with the developers of these apps trying every trick in the book to dodge security checks.

“Until now, SharkBot’s developers seem to have been focusing on the dropper in order to keep using shoppingmode Google Play Store to distribute their malware in the latest campaigns,” researchers Alberto Segura and Mike Stokkel said.

https://thehackernews.com/2022/09/fake-antivirus-and-cleaner-apps-caught.html?

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:49 am, Mai 19, 2025
Wetter-Symbol 12°C
L: 11° | H: 13°
overcast clouds
Luftfeuchtigkeit: 78 %
Druck: 1021 mb
Wind: 7 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:02 am
Sonnenuntergang: 8:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
11° | 13°°C 0 mm 0% 11 mph 78 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 21°°C 0 mm 0% 9 mph 69 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
14° | 22°°C 0 mm 0% 12 mph 63 % 1020 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 12 mph 64 % 1023 mb 0 mm/h
Fr. Mai 23 10:00 pm
Wetter-Symbol
7° | 19°°C 0 mm 0% 9 mph 69 % 1024 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
12° | 14°°C 0 mm 0% 7 mph 78 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
14° | 18°°C 0 mm 0% 9 mph 67 % 1021 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 19°°C 0 mm 0% 11 mph 52 % 1020 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 63 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 5 mph 69 % 1021 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 63 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,905.24
-0.73%
Ethereum(ETH)
€2,143.42
-4.20%
Fesseln(USDT)
€0.89
0.00%
XRP(XRP)
€2.07
-3.03%
Solana(SOL)
€144.61
-4.69%
USDC(USDC)
€0.89
0.01%
Dogecoin(DOGE)
€0.195265
-0.82%
Shiba Inu(SHIB)
€0.000013
-2.92%
Pepe(PEPE)
€0.000012
1.15%
Peanut das Eichhörnchen(PNUT)
€0.288878
-6.55%
Nach oben scrollen