European Bank Customers Targeted in SpyNote Android Trojan Campaign

Share:

Various European customers of different banks are being targeted by an Android banking trojan called SpyNote as part of an aggressive campaign detected in June and July 2023.

The spyware is distributed through email phishing or smishing campaigns and the fraudulent activities are executed with a combination of remote access trojan (RAT) capabilities and vishing attack, Italian cybersecurity firm Cleafy said in a technical analysis released Monday.

SpyNote, also called SpyMax, is similar to other Android banking Trojans in that it requires Android’s accessibility permissions in order to grant itself other necessary permissions and gather sensitive data from infected devices. What makes the malware strain notable is its dual functions as spyware and perform bank fraud.

The attack chains commence with a bogus SMS message urging users to install a banking app by clicking on the accompanying link, redirecting the victim to the legitimate TeamViewer QuickSupport app available on the Google Play Store.

TeamViewer has been adopted by several [threat actors] to execute fraud operations through social engineering attacks, security researcher Francesco Iubatti said. In particular, the attacker calls the victim, impersonating bank operators, and performs fraudulent transactions directly on the victim’s device.

The idea is to use TeamViewer as a conduit to gain remote access to the victim’s phone, and stealthily install the malware. The various kinds of information harvested by SpyNote include geolocation data, keystrokes, screen recordings, and SMS messages to bypass SMS-based two-factor authentication (2FA).

The disclosure comes as the hack-for-hire operation known as Bahamut has been linked to a new campaign targeting individuals in the Middle East and South Asia regions with the goal of installing a dummy chat app named SafeChat that conceals an Android malware dubbed CoverIm.

Delivered to victims via WhatsApp, the app houses identical features as that of SpyNote, requesting for accessibility permissions and others to collect call logs, contacts, files, location, SMS messages, as well as install additional apps and steal data from Facebook Messenger, imo, Signal, Telegram, Viber, and WhatsApp.

Cyfirma, which uncovered the latest activity, said the tactics employed by this threat actor overlap with another nation-state actor known as the DoNot Team, which was recently observed utilizing rogue Android apps published to the Play Store to infect individuals located in Pakistan.

While the exact specifics of the social engineering aspect of the attack is unclear, Bahamut is known to rely on fictitious personas on Facebook and Instagram, pretending to be tech recruiters at large tech companies, journalists, students, and activists to trick unwitting users into downloading malware on their devices.

Bahamut used a range of tactics to host and distribute malware, including running a network of malicious domains purporting to offer secure chat, file-sharing, connectivity services, or news applications, Meta revealed in May 2023. Some of them spoofed the domains of regional media outlets, political organizations, or legitimate app stores, likely to make their links appear more legitimate.

 

(c) Thin

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:36 am, May 18, 2025
weather icon 12°C
L: 11° | H: 14°
scattered clouds
Humidity: 68 %
Pressure: 1020 mb
Wind: 3 mph E
Wind Gust: 10 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 29%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:04 am
Sunset: 8:49 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
11° | 14°°C 0 mm 0% 8 mph 64 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
9° | 19°°C 0.2 mm 20% 12 mph 80 % 1022 mb 0 mm/h
Tue May 20 10:00 pm
weather icon
9° | 21°°C 0 mm 0% 8 mph 71 % 1023 mb 0 mm/h
Wed May 21 10:00 pm
weather icon
12° | 18°°C 1 mm 100% 7 mph 89 % 1020 mb 0 mm/h
Thu May 22 10:00 pm
weather icon
9° | 19°°C 0 mm 0% 8 mph 59 % 1022 mb 0 mm/h
Today 1:00 pm
weather icon
13° | 15°°C 0 mm 0% 8 mph 62 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 18°°C 0 mm 0% 8 mph 49 % 1019 mb 0 mm/h
Today 7:00 pm
weather icon
16° | 16°°C 0 mm 0% 7 mph 47 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 7 mph 64 % 1020 mb 0 mm/h
Tomorrow 1:00 am
weather icon
12° | 12°°C 0 mm 0% 7 mph 71 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
9° | 9°°C 0 mm 0% 6 mph 80 % 1021 mb 0 mm/h
Tomorrow 7:00 am
weather icon
10° | 10°°C 0 mm 0% 6 mph 74 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 55 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,162.81
0.90%
Ethereum(ETH)
€2,257.10
1.66%
Tether(USDT)
€0.90
0.00%
XRP(XRP)
€2.15
1.28%
Solana(SOL)
€153.46
1.98%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.200747
4.01%
Shiba Inu(SHIB)
€0.000013
4.62%
Pepe(PEPE)
€0.000012
7.37%
Peanut the Squirrel(PNUT)
€0.321460
25.80%
Scroll to Top