ANDROIDOS_BANKERSMS.HRX

 Analysis by: Kenny Ye

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes


  TECHNICAL DETAILS

File Size:

172541 bytes

File Type:

APK

Memory Resident:

Yes

NOTES:

This family is developed based on a leaked banking Trojan source code. The purpose of the malware is to phish account login credentials and bank card information of users in Russia.

It will request for the device administrator privilege and hide its icon after launch. The stolen information is then sent to its server.

The Trojan also will block and delete the incoming SMS from the bank to hide the message from the victim. The targeted application includes most of the banks in Russia, as well as Facebook, WhatsApp, Google Play Store, or Uber.