Wednesday, January 1, 2025
HomeMalwareAndroid Spyware & Banking Trojan Attack via DNS Spoofing that Poses as...

Android Spyware & Banking Trojan Attack via DNS Spoofing that Poses as Legitimate Facebook or Chrome App

Published on

SIEM as a Service

A new wave of network attacks that uses DNS spoofing and cache poisoning method to distribute XLoader  Android Spyware and Banking Trojan.

DNS Spoofing or poisoning  is a type of cyber-attack that exploits system vulnerabilities in the domain name server to divert traffic away from legitimate servers and directs it towards fake ones

The malicious app poses a legitimate Chrome or Facebook app and it is distributed through fake by pushing a notification to a victim device.

- Advertisement - SIEM as a Service

According to TrendMicro analysis report “this new wave of network attacks since early March which for now are targeting Japan, Korea, China, Taiwan, and Hong Kong.

Upon installation, the malicious app is capable of stealing personal information, financial data and it installs additional apps to the device.

It is also capable of hijacking the device and establish persistence through administrator privileges.

How the Infection Work with DNS Spoofing

Attackers compromise the router settings and redirect the traffic to certain websites and fake drive users to the malicious domains and to download XLoader.

Once the application triggered it hides from the application list and keeps running in the background and triggers the malicious activities.

Trend Micro Researcher says “XLoader creates a provisional web server to receive the broadcast events. It can also create a simple HTTP server on the infected device to deceive victims. It shows a web phishing page whenever the affected device receives a broadcast event (i.e., if a new package is installed or if the device’s screen is on) to steal personal data, such as those keyed in for banking apps”.

The Phishing page translated to Korean, Japanese, Chinese, or English based on the device language that setup in the device. It is capable of collecting SMS details, records phone calls, steals personal and financial data from the device.

XLoader abuses WebSocket protocol over SSL/TLS to establish persistent and secure communication with C&C server, it also abuses message pack to steal the exfiltrated the data faster.

Mitigations

Setup complex password to routers.
Regularly update the Router & Firewall Firmware.
Monitoring the router’s DNS setting at regular intervals.
Stay wise against social engineering attacks.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

DrayTek Devices Vulnerability Let Attackers Arbitrary Commands Remotely

The DrayTek Gateway devices, more specifically the Vigor2960 and Vigor300B models, are susceptible to...

New Stealthy Malware Leveraging SSH Over TOR Attacking Ukrainian Military

Researchers recently discovered a malicious campaign targeting Ukrainian military personnel through fake "Army+" application...

CISA Warns of Palo Alto Networks PAN-OS Vulnerability Exploited in Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert on...

US Treasury Department Breach, Hackers Accessed Workstations

The Biden administration confirmed that a Chinese state-sponsored hacking group breached the U.S. Treasury...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

New Stealthy Malware Leveraging SSH Over TOR Attacking Ukrainian Military

Researchers recently discovered a malicious campaign targeting Ukrainian military personnel through fake "Army+" application...

Hackers Weaponize Websites With LNK File To Deliver Weaponized LZH File

The watering hole attack leverages a compromised website to deliver malware. When a user...

Lumma Stealer Attacking Users To Steal Login Credentials From Browsers

Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a...