Vultur banking malware reappears with many dangerous features
Researcher Joshua Kamp (NCC Group), said: 'Vultur has encrypted communication information between the control server (C2 server) and infected devices, impersonating legitimate applications to perform many harmful actions'.
When communication between the control server and the victim's device is encrypted, the transmitted data becomes harder for security systems to read and analyze, making it difficult to detect and prevent malicious activities. harm becomes more difficult.
What is Vultur banking malware?
Vultur is one of the first Android banking malware families with screen recording capabilities, primarily targeting banking applications to record keystrokes and remote controls. Vultur was first discovered by ThreatFabric in late March 2021.
This malware was observed to be distributed through trojanized droppers on Google Play, masquerading as authenticator apps and productivity apps to trick users into installing them.
As observed by NCC Group, dropper applications use a combination of SMS messages and phone calls to spread malware. Once installed by the user, the dropper will execute 3 related payloads (2 APKs and 1 DEX file) register the bot with the C2 server, obtain accessibility service permissions for remote access via AlphaVNC, and ngrok, while also running commands fetched from the C2 server.
One of Vultur's new features is the ability to remotely interact with an infected device, including performing clicks, scrolls, and swipes through Android accessibility services, as well as downloading, uploading, and swiping. delete, install and find files.
Additionally, the malware prevents victims from interacting with a predefined list of apps, displays custom notifications in the status bar, and even disables Keyguard to bypass screen security measures. lock up.
Vultur improves remote control
Kamp said: 'Vultur's recent developments have demonstrated a shift in focus towards maximizing remote control of infected devices. With the ability to dictate scrolling, swiping, clicking, controlling volume, blocking app launches, and even incorporating file management functionality, it's clear that the main goal is to gain full control over compromised devices. '
This development comes as Team Cymru revealed the transition of Android banking trojan Octo (also known as Coper) to operating as a service, providing malware for other threat actors to conduct. information theft.
'This malware offers many advanced features, including keystroke logging, blocking SMS messages and push notifications, and controlling the device's screen,' the company said.
Octo's campaigns are estimated to have compromised 45,000 devices, mainly spread across Portugal, Spain, Türkiye and the United States. Some other victims were in France, the Netherlands, Canada, India and Japan.
Broadcom-owned Symantec said in a news release that the malware 'targets stealing banking information, SMS messages and other confidential information from victims' devices'.
You should read it
- There is an Edge Chromium browser, invite download and experience
- What is special about E5 bio-finisher RON 92?
- Instructions for creating new Apple ID on PC or Mac using iTunes
- What is Binomo? How to register Binomo like?
- How to change iPhone wallpaper automatically when rotating the screen
- Lenovo stopped selling netbooks online
- Is backup and storage a must?
- The bright side of P2P
May be interested
- Japan invested 33 billion USD to design a new hydrogen-powered passenger aircraftthe effort is aimed at making japan the leader in passenger aircraft production - a position it has not held for more than half a century.
- Are smartphones strong enough to 'shoulder' a giant AI model?recently, google warned users to consider carefully before using ai models on android phones in general and google pixel phones, because they consume a lot of ram.
- Many US states have proposed laws banning lab-grown meatrepublican lawmakers in multiple us states are proposing laws to block the growth of lab-grown pork, chicken, tuna and other animal proteins. this food technology is rising rapidly with the backing of billionaire investors like bill gates and jeff bez
- 10 applications with the highest revenue in the worldaccording to mobile analyst appfigures, tiktok has been the highest-grossing app in the world for at least 15 months of operation, surpassing both youtube and tinder.
- Japan creates a robot with living muscles that can walk in waterjapanese scientists have created a small bipedal robot that integrates both muscle tissue and artificial materials, and can walk and change direction thanks to muscle contractions, new scientist reported. the research was published in the journal matter.
- VnDirect case 'collapsed': How dangerous is ransomware?ransomware is the type of software that causes the most financial damage to agencies and businesses through attacks and data encryption. basically, it is very difficult to decrypt encrypted data.