News: 1622810053

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Android banking malware sharply increased in the first chunk of 2021, reckons ESET

(2021/06/04)


While enterprises stagger under sustained ransomware attacks, Android users are increasingly being targeted by banking malware, with Slovakian infosec firm ESET reckoning it had seen a 159 per cent increase in such malicious software over the last few months.

Even though banking malware aimed at users of the Google mobile OS sharply increased in popularity overall mobile threat detections on the Google-owned operating system declined by 18.8 per cent quarter-on-quarter, said ESET.

“Android Banking Malware has continued to grow substantially, during T1* 2021 by 158.7 per cent. On our top 10 list, Android Banking Malware is represented by Android/TrojanDropper.Agent trojan (26.4 per cent), which was the most widespread Android threat overall in T1, and by Android/Spy.Banker trojan (but at only 2.0 per cent),” said the company in a report published today.

[1]

Oddly, a flaw in Android Webview that [2]existed for seven hours in March caused enough people to download ESET’s mobile antivirus to merit a specific mention in the report:

[3]

[4]

“It caused app crashes to a point that made users start investigating by extensively downloading cybersecurity apps, including ours. Even though this issue lasted for only around seven hours, we started to receive a lot of Android threat data from newly scanned devices.”

Tongue in cheek, the firm added: “It is, however, interesting to see a real-life example of what can cause Android users to suddenly become interested in cybersecurity protection!”

[5]Ahem, Huawei, your USB LTE stick has a vuln. I SAID AHEM, Huawei, are you listening?

[6]Feds seize two domains used by SolarWinds intruders for malware spear-phishing op

[7]What happens when a security hole is fixed in WebKit's source but not released as a patch by Apple? Let's find out

[8]Apple patches macOS flaw exploited by malware to secretly snap screenshots

ESET also said it had seen Russia’s FSB foreign intelligence spy agency, which the security shop tracks under the name Turla, running an espionage campaign on “a Ministry of Foreign Affairs in Eastern Europe”. A backdoor planted on a ministry server combined with PowerShell scripts gave the game away, the company said, naming the exploit NETVulture. The FSB used OneDrive for command ‘n’ control, relying on “Microsoft Graph authentication to access the cloud storage”, in much the same way that Sophos [9]warned of earlier this year .

On top of that the Russians had used a 2020 RCE vuln in Microsoft Exchange ( [10]CVE-2020-0688 ) to plant the [11]China Chopper web shell . “Despite being low profile in the last months, this shows that Turla still has its sights set on its regular targets, especially diplomats, and is expanding its malware arsenal,” said ESET.

[12]

The full report can be read via Eset’s Welivesecurity [13]blog . ®

Timenote

* Strangely, ESET has eschewed the global quarterly standard for breaking up the year into digestible chunks and now segments it into thirds of four months each. This makes it difficult to accurately compare ESET research with other infosec companies’ output, especially when it comes to trends.

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YLpOHpudBFNz0BvVhwdN7QAAAMg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2021/03/23/google_webview_patch/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YLpOHpudBFNz0BvVhwdN7QAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YLpOHpudBFNz0BvVhwdN7QAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/06/02/huawei_lte_usb_stick_vulnerability/

[6] https://www.theregister.com/2021/06/02/feds_seize_nobelium/

[7] https://www.theregister.com/2021/05/27/safari_webkit_bug/

[8] https://www.theregister.com/2021/05/24/ios_macos_patches/

[9] https://www.theregister.com/2021/04/21/sophos_research/

[10] https://www.theregister.com/2020/02/11/patch_tuesday_february_2020/

[11] https://www.theregister.com/2020/09/16/iran_targets_citrix_pulse_secure_f5_vpns/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YLpOHpudBFNz0BvVhwdN7QAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.welivesecurity.com/2021/06/03/eset-threat-report-t12021/

[14] https://whitepapers.theregister.com/

How many Android devices are secure in any case?

johnB

As updates for Android only run for a couple pf years I'd guess most Androids are insecure by virtue of running an out-of-date OS.

So running a banking app on Android seems a dubious practice at best. Even if the OS is currently up to date, it'll probably be no longer so by the time the device is disposed of.

Re: How many Android devices are secure in any case?

vtcodger

By the time a vendor has identified a vulnerability, crafted a patch, tested the fix, crafted a further patch because the first was incorrect or incomplete, tested that, and eventually distributed an update, the malware folks have probably moved on to exploiting a different vulnerability. In the current vernacular, the malware people are more agile . And they can afford to be. If their current product works poorly, there's always tomorrow. The same, unfortunately does not apply to you.

Given the current state of internet security, it appears to me that frantically patching your software is the "Pearl Harbor" defense -- protecting yourself from the last war's technology. Not totally useless probably, but likely not very effective.

So, what to do? AFAICS at present and for the immediate future, I'd suggest keeping your financial affairs off the internet to the greatest extent possible. Use paper and the postal service where possible. Bank physically, not electronically. If your country's consumer legal protections are weak, consider using cash or prepaid debit cards. Yes, that's inconvenient. Extremely so. But, as we say here in the states "It is what it is."

Re: How many Android devices are secure in any case?

katrinab

Or:

The malware authors only need to get lucky once.

Google and the smartphone vendors need to get lucky every single time.

JDPower666

"now segments it into thirds of four months each"

Perhaps they could make it quarters of four months. Perhaps give it a name. Something like "a month"

Tongue in cheek?

Anonymous Coward

"Tongue in cheek, the firm added: “It is, however, interesting to see a real-life example of what can cause Android users to suddenly become interested in cybersecurity protection!”"

I have witnessed millions of Android users "suddenly become interested in cybersecurity protection" due to fake virus warnings pushed by advertising companies.

Here's just one example of a script that is used to fingerprint Android devices and then send fake virus warnings that lead to bogus "antivirus" apps on Google Play and even push malicious apk's disguised as an adblock app:

hxxps://d2sbzwmcg5amr3.cloudfront(.)net/?wzbsd=910128

URL scan link:

https://urlscan.io/result/c7b9e50d-e3d5-472b-875e-c7813d986382/

(Amazon hostmaster has been notified but I haven't heard anything back)

indent does _not_ solve the problem of:
* buggers who introduce wrappers for standard kernel stuff - like,
say it, typedef int Int32; and sprinkle their crap with
per-architecture ifdefs.

- Alexander Viro on coding style