216.73.216.6

Analysis of New Mobile Banking Malware

· Published 01/04/2025 21:23 · Modified 02/04/2025 08:28

Export JSON

Essential information

Published
01/04/2025 21:23
Modified
02/04/2025 08:28
Tags
2025-04-01 android banking credential stealing data exfiltration otp theft persistence phishing salvador stealer sms interception
Related entities
1 malware, 3 others

Description

is a newly discovered malware that poses as a application to steal sensitive user information. It employs a multi-stage attack chain, utilizing a dropper APK to install the main payload. The malware incorporates a website within the app to collect personal and data, including Aadhaar numbers, PAN card details, and net credentials. It exfiltrates stolen information in real-time to both a server and a Telegram-based Command and Control server. also intercepts SMS messages to capture one-time passwords and verification codes, bypassing two-factor authentication. The malware demonstrates mechanisms, automatically restarting itself if stopped and surviving device reboots. Analysis revealed exposed infrastructure, including an accessible admin panel, potentially linking the attacker to India.

External references