/?pid=18827

Updated:06:47 PM EDT Apr 24


this is ggmania.com subsite Android Banking Trojan Svpeng Adds Keylogger - TechAmok

Android Banking Trojan Svpeng Adds Keylogger - [security]
07:13 PM EDT - Aug,01 2017 - post a comment

The authors behind the Android banking malware family Svpeng have added a keylogger to a recent strain, giving attackers yet another way to steal sensitive data.

Roman Unuchek, a senior malware analyst with Kaspersky Lab, said Monday he spotted a new variant of the Trojan in mid-July. Unuchek says the keylogger takes advantage of Accessibility Services, an Android feature that assists users with disabilities or assists users to access apps while driving.

Unuchek specializes in digging up Android malware; earlier this summer he helped alert Google of two apps in its Play marketplace that were really Ztorg Trojans and another app that was a rooting Trojan, Dvmap.

According to the researcher the most recent iteration of Svpeng checks the device's language. If the language isn't Russian, it asks the device to use Accessibility Services, something that can subject the device to a number of dangerous outcomes.

It grants itself device administrator rights, draws itself over other apps, installs itself as a default SMS app, and grants itself some dynamic permissions that include the ability to send and receive SMS, make calls, and read contacts, Unuchek wrote Monday, Furthermore, using its newly gained abilities the Trojan can block any attempt to remove device administrator rights thereby preventing its uninstallation.

Once afforded the ability to access to the inner workings of other apps on the device, Unuchek says Svpeng can steal text entered on other apps and take screenshots, information that's promptly fired off to the attackers' command and control server.

Unuchek said that as part of his research he managed to intercept an encrypted configuration file from the malware's C&C server. The file helped him determine some of the sites and services that Svpeng targets. He claims the file contained phishing URLs for both the PayPal and eBay mobile apps, along with URLs for banking apps from the UK, Germany, Turkey, Australia, France, Poland, and Singapore.

The file also contained an overlay for a rewards app not a financial app: Speedy Rewards, an app distributed by the US gas station/convenience store chain Speedway.

In addition to including URLs, the file helps the malware receive the following commands from the server:

  • To send SMS
  • To collect info (Contacts, installed apps and call logs)
  • To collect all SMS from the device
  • To open URL
  • To start stealing incoming SMS

The most recent version of the Trojan, dubbed Trojan-Banker.AndroidOS.Svpeng.ae, isn't exactly widely deployed, Unuchek says. Only a small number of users were attacked over the course of a week, but it could stretch further. While the malware may have not hit a lot of users, those that were hit came from all corners of Europe 23 countries, including Russia, Germany, Turkey, Poland, and France, according to Unuchek.



Add your comment (free registrationrequired)

Short overview of recent news articles

Apr,24 2024 President Biden signs TikTok bill into law
Apr,24 2024 The Humble PC
Apr,24 2024 Researchers have unlocked the 'Holy Grail' of memory technology
Apr,24 2024 The Best Gaming GPU Ever Released, Nvidia GeForce GTX 1080 Ti, 2024
Apr,24 2024 Your Own Private Network Attached Storage Solution by UGREEN
Apr,23 2024 ATLAS | Official Trailer | Netflix
Apr,22 2024 The World's Fastest CPU (Technically...) - Intel i9-14900KS
Apr,22 2024 We can do THIS now! - Lumafield CT Scanner
Apr,21 2024 Huawei Pura 70 Ultra - Apple Should be WORRIED
Apr,21 2024 Sony 2024 TV Lineup Revealed
Apr,20 2024 ICE - A Thousand Suns / Episode 1
Apr,20 2024 Minisforum V3 AMD Tablet Review
Apr,20 2024 AMD & Intel SLASH CPU Prices!
Apr,20 2024 EK is Imploding: Not Paying Employees, Partners, & Suppliers
Apr,20 2024 Backing Up My NAS To My... Parents' House?
Apr,20 2024 NEW Ryzen APU BEATS RTX 40 GPUs!
Apr,20 2024 (Live) Black Tape Project - All New Raw and Uncut - LA Fashion Week
Apr,19 2024 NVIDIA Geforce 552.22 WHQL Driver
Apr,19 2024 You Deserve this much OLED - AORUS CO49DQ
Apr,19 2024 Unreal Engine 5.4 looks ULTRA PHOTOREALISTIC
Apr,18 2024 Radeon RX 5700 XT vs. 7700 XT, 2024 Revisit
Apr,18 2024 I Will Build You a PC Right Now!
Apr,17 2024 These games carry REAL security risks! BEWARE!
Apr,17 2024 Visible First to Offer Annual Payment Plan, with Discount up to 26%
Apr,17 2024 Is Coding Still Worth Learning in 2024?
Apr,17 2024 All New Atlas - Boston Dynamics
Apr,16 2024 The NEW Chip Inside Your Phone! (NPUs)
Apr,16 2024 XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel!
Apr,15 2024 The Most 2024 Laptop - Razer Blade 14 Review
Apr,15 2024 NEVER install these programs on your PC... EVER!!!
Apr,14 2024 Use Live Translate on Galaxy S24 series to translate a call's
Apr,14 2024 I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam?
Apr,13 2024 Samsung Galaxy Ring - This Just Got Interesting
Apr,13 2024 Piracy Is Over Party - WAN Show April 12, 2024
Apr,13 2024 Conan O'Brien Needs a Doctor While Eating Spicy Wings
Apr,13 2024 Beatbox Jcob recreats every sound
Apr,13 2024 Intel is Gunning for NVIDIA
Apr,13 2024 Building a Budget DIY Home Surveillance System
Apr,12 2024 Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop
Apr,11 2024 DARK MATTER Trailer (2024) New Sci-Fi Movies 4K
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs