Android banking malware sharply increased in the first chunk of 2021, reckons ESET
- Reference: 1622810053
- News link: https://www.theregister.co.uk/2021/06/04/eset_threat_android/
- Source link:
Even though banking malware aimed at users of the Google mobile OS sharply increased in popularity overall mobile threat detections on the Google-owned operating system declined by 18.8 per cent quarter-on-quarter, said ESET.
“Android Banking Malware has continued to grow substantially, during T1* 2021 by 158.7 per cent. On our top 10 list, Android Banking Malware is represented by Android/TrojanDropper.Agent trojan (26.4 per cent), which was the most widespread Android threat overall in T1, and by Android/Spy.Banker trojan (but at only 2.0 per cent),” said the company in a report published today.
[1]
Oddly, a flaw in Android Webview that [2]existed for seven hours in March caused enough people to download ESET’s mobile antivirus to merit a specific mention in the report:
[3]
[4]
“It caused app crashes to a point that made users start investigating by extensively downloading cybersecurity apps, including ours. Even though this issue lasted for only around seven hours, we started to receive a lot of Android threat data from newly scanned devices.”
Tongue in cheek, the firm added: “It is, however, interesting to see a real-life example of what can cause Android users to suddenly become interested in cybersecurity protection!”
[5]Ahem, Huawei, your USB LTE stick has a vuln. I SAID AHEM, Huawei, are you listening?
[6]Feds seize two domains used by SolarWinds intruders for malware spear-phishing op
[7]What happens when a security hole is fixed in WebKit's source but not released as a patch by Apple? Let's find out
[8]Apple patches macOS flaw exploited by malware to secretly snap screenshots
ESET also said it had seen Russia’s FSB foreign intelligence spy agency, which the security shop tracks under the name Turla, running an espionage campaign on “a Ministry of Foreign Affairs in Eastern Europe”. A backdoor planted on a ministry server combined with PowerShell scripts gave the game away, the company said, naming the exploit NETVulture. The FSB used OneDrive for command ‘n’ control, relying on “Microsoft Graph authentication to access the cloud storage”, in much the same way that Sophos [9]warned of earlier this year .
On top of that the Russians had used a 2020 RCE vuln in Microsoft Exchange ( [10]CVE-2020-0688 ) to plant the [11]China Chopper web shell . “Despite being low profile in the last months, this shows that Turla still has its sights set on its regular targets, especially diplomats, and is expanding its malware arsenal,” said ESET.
[12]
The full report can be read via Eset’s Welivesecurity [13]blog . ®
Timenote
* Strangely, ESET has eschewed the global quarterly standard for breaking up the year into digestible chunks and now segments it into thirds of four months each. This makes it difficult to accurately compare ESET research with other infosec companies’ output, especially when it comes to trends.
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YLpOHpudBFNz0BvVhwdN7QAAAMg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2021/03/23/google_webview_patch/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YLpOHpudBFNz0BvVhwdN7QAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YLpOHpudBFNz0BvVhwdN7QAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2021/06/02/huawei_lte_usb_stick_vulnerability/
[6] https://www.theregister.com/2021/06/02/feds_seize_nobelium/
[7] https://www.theregister.com/2021/05/27/safari_webkit_bug/
[8] https://www.theregister.com/2021/05/24/ios_macos_patches/
[9] https://www.theregister.com/2021/04/21/sophos_research/
[10] https://www.theregister.com/2020/02/11/patch_tuesday_february_2020/
[11] https://www.theregister.com/2020/09/16/iran_targets_citrix_pulse_secure_f5_vpns/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YLpOHpudBFNz0BvVhwdN7QAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.welivesecurity.com/2021/06/03/eset-threat-report-t12021/
[14] https://whitepapers.theregister.com/
Re: How many Android devices are secure in any case?
By the time a vendor has identified a vulnerability, crafted a patch, tested the fix, crafted a further patch because the first was incorrect or incomplete, tested that, and eventually distributed an update, the malware folks have probably moved on to exploiting a different vulnerability. In the current vernacular, the malware people are more agile . And they can afford to be. If their current product works poorly, there's always tomorrow. The same, unfortunately does not apply to you.
Given the current state of internet security, it appears to me that frantically patching your software is the "Pearl Harbor" defense -- protecting yourself from the last war's technology. Not totally useless probably, but likely not very effective.
So, what to do? AFAICS at present and for the immediate future, I'd suggest keeping your financial affairs off the internet to the greatest extent possible. Use paper and the postal service where possible. Bank physically, not electronically. If your country's consumer legal protections are weak, consider using cash or prepaid debit cards. Yes, that's inconvenient. Extremely so. But, as we say here in the states "It is what it is."
Re: How many Android devices are secure in any case?
Or:
The malware authors only need to get lucky once.
Google and the smartphone vendors need to get lucky every single time.
"now segments it into thirds of four months each"
Perhaps they could make it quarters of four months. Perhaps give it a name. Something like "a month"
Tongue in cheek?
"Tongue in cheek, the firm added: “It is, however, interesting to see a real-life example of what can cause Android users to suddenly become interested in cybersecurity protection!”"
I have witnessed millions of Android users "suddenly become interested in cybersecurity protection" due to fake virus warnings pushed by advertising companies.
Here's just one example of a script that is used to fingerprint Android devices and then send fake virus warnings that lead to bogus "antivirus" apps on Google Play and even push malicious apk's disguised as an adblock app:
hxxps://d2sbzwmcg5amr3.cloudfront(.)net/?wzbsd=910128
URL scan link:
https://urlscan.io/result/c7b9e50d-e3d5-472b-875e-c7813d986382/
(Amazon hostmaster has been notified but I haven't heard anything back)
How many Android devices are secure in any case?
As updates for Android only run for a couple pf years I'd guess most Androids are insecure by virtue of running an out-of-date OS.
So running a banking app on Android seems a dubious practice at best. Even if the OS is currently up to date, it'll probably be no longer so by the time the device is disposed of.