Alcune app anti-virus su Play Store diffondono un banking malware

Check Point Research (CPR), la divisione Threat Intelligence di Check Point® Software Technologies Ltd.(NASDAQ: CHKP), il principale fornitore di soluzioni per la sicurezza informatica a livello globale, ha trovato sei applicazioni su Google Play Store che diffondevano banking malware spacciandosi per soluzioni anti-virus. Conosciuto come Sharkbot, il malware ruba credenziali e informazioni bancarie.

CPR ha contato oltre 1.000 indirizzi IP unici di dispositivi infetti, soprattutto in Italia. Tuttavia, i dati di Google Play Store indicano che le applicazioni dannose sono state scaricate più di 11.000 volte. Sharkbot attira le sue vittime con notifiche push, inducendo gli utenti a inserire credenziali con la compilazione di moduli. Quando l’utente inserisce le proprie credenziali in queste finestre, i dati compromessi vengono inviati a un server maligno.

CPR sospetta che gli aggressori siano di lingua russa e avverte gli utenti Android di stare molto attenti anche nel download di soluzioni anti-virus, le quali dovrebbero proteggerli dai virus stessi.

  • Il 62% delle vittime sono state trovate in Italia; il 36% nel Regno Unito, il 2% in altri Paesi.
  • Gli hacker hanno implementato una funzione di geo-fencing, che ignora gli utenti in Cina, India, Romania, Russia, Ucraina o Bielorussia.
  • CPR ha comunicato responsabilmente i risultati a Google, che ha rimosso le app dannose.

..//

The Six Malicious Applications

Figure 1. 

Four of the applications came from three developer accounts, Zbynek Adamcik, Adelmio Pagnotto and Bingo Like Inc. When CPR checked the history of these accounts, they saw that two of them were active in the fall of 2021. Some of the applications linked to these accounts were removed from Google Play, but still exist in unofficial markets. This could mean that the actor behind the applications is trying to stay under the radar while still involved in malicious activity. 

Victims

CPR was able to collect statistics for one week. During this time, CPR counted over 1,000 IPs of victims. Each day, the number of victims increased by roughly 100. According to Google Play statistics, the six malicious applications spotted by CPR were downloaded over 11,000 times. Most of the victims are in UK and Italy.

Figure 2. % of victims by country

Attack Methodology 

  • Incline user to grant accessibility service permissions for application
  • After that, the malware gains control of a large part of the victim’s device
  • Threat actors can also send push notifications to victims containing malicious links 

Attribution

CPR does not have enough evidence to make an attribution. We can assume that the malware authors speak Russian. Furthermore, the malware will not run its malicious functionality if the device’s locale is in China, India, Romania, Russia, Ukraine or Belarus. 

Responsible Disclosure

Immediately after identifying these applications that spread Sharkbot, CPR reported these findings to Google. After examining the apps, Google proceeded to permanently remove these applications on Google Play store. On the same day CPR reported the findings to Google, the NCC group published a separate research about Sharkbot, mentioning one of the malicious apps.

Alexander Chailytko, Cyber Security, Research & Innovation Manager at Check Point Software: 

We discovered six applications on Google’s Play Store that were spreading Sharkbot malware. This malware steals credentials and banking information. It is obviously very dangerous. Looking at the install count we can assume that the threat actor hit the bulls-eye for their method of malware spread. The threat actor strategically chose a location of applications on Google Play that have users’ trust. What’s also noteworthy here is that the threat actors push messages to victims containing malicious links, which leads to widespread adoption. All in all, the use of push-messages by the threat actors requesting an answer from users is an unusual spreading technique. I think it’s important for all Android users to know that they should think twice before downloading any anti-virus solution from the Play Store. It could be Sharkbot.” 

Safety Tips for Android Users

  • Install applications only from trusted and verified publishers.
  • If you see an application from a new publisher, search for analogs from a trusted one.
  • Report to Google any seemingly suspicious applications you encounter.
Translate »