ANDROIDOS_FAKEBANK.HRXK

 Analysis by: Echo Duan

 THREAT SUBTYPE:

Information Stealer

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Backdoor

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Android malware masquerades as Adobe Flash Player with a legitimate-looking icon.

It gathers the package names of installed applications including mobile banking apps and sends them to the remote server.

If any of installed app is a banking app, the malware appears over the launched banking application. The malware behaves like a lock screen, which cannot be terminated without the user entering their login credentials.

  TECHNICAL DETAILS

File Size:

29,768 bytes

File Type:

APK

Memory Resident:

Yes

NOTES:

This Android malware masquerades as Adobe Flash Player with a legitimate-looking icon.

After downloading and installing the app, the user is requested to grant the application device administrator rights. This routine prevents it from being uninstalled from the device. The icon is then hidden from the user’s view, but the malware remains active in the background.

It intercepts SMS to send user SMS information to a remote server or via sending an SMS.

It then gathers the package names of installed applications including mobile banking apps and sends them to the remote server.

If any of installed app is a banking app, the malware appears over the launched banking application. The malware behaves like a lock screen, which cannot be terminated without the user entering their login credentials.

  SOLUTION

Minimum Scan Engine:

9.800

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:


Did this description help? Tell us how we did.