A recently discovered Android Trojan, dubbed “MMRat,” poses a serious threat to mobile banking security. Unlike other forms of malware, this Trojan is designed to evade detection from traditional antivirus software.
The security experts at TrendMicro have identified the Trojan as AndroidOS_MMRat.HRX, warning users to be cautious when downloading new apps or accessing their banking information from their Android devices.
This group has been committing bank fraud by targeting mobile users in Southeast Asia since late June 2023.
The sophisticated malware, operating under the package name com.mm.user, is equipped with advanced capabilities, including capturing user input, remote device control, and data exfiltration.
MMRat utilizes deceptive phishing websites, posing as legitimate app stores, to distribute its payload.
These phishing sites are tailored to specific language demographics, suggesting a targeted approach to victim selection.
The exact mechanism of how these malicious links find their way to victims’ devices remains unclear. One notable aspect of MMRat’s infiltration is its complete evasion from detection.
Even on VirusTotal, the malware has remained undetected, underscoring the effectiveness of its tactics.
The sequence of events involving MMRat’s bank fraud operations unfolds as follows:
The threat actor can remotely wake up the device, unlock the screen, and initiate bank fraud. Additionally, they can visualize the device screen in real-time via screen capturing.
After accomplishing its fraudulent objectives, MMRat uninstalls itself, leaving minimal traces on the system.
Impersonation and Persistence MMRat disguises itself as an official app, presenting victims with phishing websites upon launch. It establishes a receiver for system events, ensuring persistence by launching a 1×1-sized pixel activity.
Network Communication MMRat communicates with a remote server through different ports, using a customized command-and-control (C&C) protocol based on protocol buffers (Protobuf). This unique approach enhances data transfer efficiency, which is particularly useful for transferring large data volumes.
User Terminal State MMRat employs Android Accessibility to capture user actions and screen content. This unconventional method focuses on text data and bypasses the FLAG_SECURE protection.
Screen Capturing MMRat captures real-time screen content via the MediaProjection API and the “user terminal state” approach. It can stream screen content to a remote server in real-time, providing the threat actor with a live view of the device.
Remote Control The malware uses the Accessibility service to remotely control the victim’s device remotely, performing actions like gestures and inputting text. This aids in bank fraud execution.
Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware
To safeguard against MMRat and similar threats, users are advised to:
Keep informed about the latest Cyber Security News by following us on Google News, Linkedin, Twitter, and Facebook.
The VIPKeyLogger infostealer, exhibiting similarities to the Snake Keylogger, is actively circulating through phishing campaigns. …
INTERPOL has called for the term "romance baiting" to replace "pig butchering," a phrase widely…
Cybersecurity experts are sounding the alarm over a new strain of malware dubbed "I2PRAT," which…
A new cyber campaign by the advanced persistent threat (APT) group Earth Koshchei has brought…
Recent research has linked a series of cyberattacks to The Mask group, as one notable…
RiseLoader, a new malware family discovered in October 2024, leverages a custom TCP-based binary protocol…