Monday, March 3, 2025
HomeMalwareFakeBank Malware Layered Obfuscation Technique Replace a Default SMS App to Stealing...

FakeBank Malware Layered Obfuscation Technique Replace a Default SMS App to Stealing Highly Sensitive Data

Published on

SIEM as a Service

Follow Us on Google News

A New persistent malware family called FakeBank spreading across Russian speaking nations and targetting Russian banks with sophisticated Obfuscation technique to steal highly sensitive information.

Identified samples are mainly abusing Legitimate SMS and MMS based management applications.

This malware specifically targeting to gain the financial information from the SMS applications and periodically gathering pieces of information from the mobile banking system.

This critical malware has been detected in few countries such as Russia, China, Ukraine, Romania, Germany and other Russian speaking countries.

Also Read:  Fourth Fappening – Hacker Pleads Guilty to Hacking into iCloud accounts of Celebrities

FakeBank Malware Intercepting the Victims SMS

Once the user gets infected, this tricky malware will be connected to the internet and establish a connection to its Command & Control server.

Later it used to gathering an information about the antivirus software with this target machine before it starts its malicious behavior.

Once its find and antivirus software then it simply exits without performing any malicious activities using its persistent capability which helps to remain flying under the radar.

This malware stealing the information such as phone numbers, a list of installed banking apps, the balance on any linked bank card, and even location information, later it will upload the collected information to Its C&C server.

once this Malware installed on the Victims machine, an Icon of this malware app has to display in apps screen and ask for some sensitive permissions such as device administration.

Later it asks user to replace the default SMS app and once the replacement will done then it silently disappears from the screen and malicious behavior gets started.

According to Trend Micro, all this access to the device’s SMS gives the malware an avenue to silently steal money from users’ bank account. Since users bind their bank accounts to their device and receive notifications on the same device, the malware can intercept sensitive account information. It can then reset bank account passwords through received security code messages and start transferring money.

Layered Obfuscation

It also using 2 Layers that provides more obfuscation techniques to evade the detection.

First Layer used for shell protection that provides to APKs to avoid the shellcode detection.

Second layer confusion tactic to make the code harder to understand and also it encrypts all the string, system calls, functions and class name. it using (DES/BASE64)  standard encryption technique.

“The malware has registered numerous C&C domains and many of the domain names are recent, with some still alive.

These C&C domains have common IP addresses (195.22.126.81 and 195.22.126.160) that are located in Poland Warmia-Masuria. Other IP addresses (185.110.132.0 &  185.110.132.255) are located in Russia.” Trend Micro said.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in...

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...