Xenomorph Malware Strikes At The Heart Of The US Crypto Community – Details

Share This Post

A recent discovery by security experts has revealed the existence of a malware that specifically targets Android users in the US, Canada, Italy, Portugal, Spain, and Belgium.

Known as Xenomorph, the perpetrators behind this highly advanced Android banking trojan have been consistently directing their efforts towards European users for more than a year. However, they have recently expanded their operations to include consumers of over 25 American financial institutions.

The Xenomorph has returned, and this iteration is even more lethal than ever. Now a more serious danger, it has spread to more than 100 financial and cryptocurrency apps, according to analysts.

Phishing Tactics And Malware Distribution

The current Xenomorph campaign began in mid-August, according to analysts at cybersecurity firm ThreatFabric, who have been monitoring the malware’s activity since February 2022.

The malware authors’ latest campaign involves phishing URLs that encourage users to update their Chrome browsers and download the dangerous APK. The malware is still using overlay techniques to collect data, but now it is now going after US banks and a variety of cryptocurrency apps.

ThreatFabric analysts gained access to the malware operator’s payload hosting infrastructure by taking advantage of the operator’s lax security procedures.

The malware’s Private Loader, the Windows information thieves RisePro and LummaC2, and the Android malware versions Medusa and Cabassous were among the other harmful payloads they found there.

A noteworthy characteristic of the latest iteration of Xenomorph pertains to its advanced and adaptable Automatic movement System (ATS) structure, which facilitates the automated movement of cash from a compromised device to one controlled by an attacker.

Xenomorph Goes After Banks

The ATS engine of the Xenomorph malware has several modules that enable threat actors to gain control over compromised devices and carry out a range of malicious activities.

The malware targets Chase, Amex, Ally, Citi Mobile, Citizens Bank, Bank of America, and Discover Mobile consumers. ThreatFabric researchers found new trojan samples that target Bitcoin, Binance, and Coinbase.

The Xenomorph banking virus targeted 56 European banks employing screen overlay phishing in early 2022. Google Play delivered it to over 50,000 users.

Hadoken Security: The Malware Brains

The firm behind it, “Hadoken Security,” improved the virus and released a modular, flexible version in June 2022. Xenomorph was one of the top 10 banking trojans and a Zimperium “major threat” by then.

Depending on the demographic, each Xenomorph sample has about a hundred overlays that target various banks and cryptocurrency apps.

Meanwhile, users should exercise caution when urged to upgrade their mobile browsers, as these requests are often hidden spyware.

Featured image from Bleeping Computer

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Bitcoin Closing In Fast On $90,000 As Post-Election Rally Continues

Crypto investors are getting excited about the latest price surge of Bitcoin, which occurred only days after the US election, fueled by favorable market sentiment toward the digital currency industry

Crypto Bull Market Arrives: Analysts Say ‘Buy Everything You Can’

Bernstein analysts foresee a crypto bull market fueled by Trump’s pro-bitcoin stance, urging investors to seize this opportunity for gains, with a $200K bitcoin target by 2025 Bernstein Calls

Tourist’s Nightmare In Thailand: $250K In USDT Taken In Hotel Armed Robbery

Crypto is a popular target for cybercriminals, who rely on its anonymity and lack of regulation These crimes often target individuals online through hacking and ransomware However, there have been a

Why is Bitcoin Price Up Today?

The post Why is Bitcoin Price Up Today appeared first on Coinpedia Fintech News After breaking the $80,000 barrier on Monday, Bitcoin soared to nearly $90,000 by Tuesday, marking a historic

Ethereum ETFs surge after US election, approaching positive net flows

Spot Ethereum (ETH) exchange-traded funds (ETF) amassed $2955 million in inflows on Nov 11, their highest daily positive net flow since launch — bringing them $29 million away from positive net

Bitfufu Secures $100 Million Credit Line From Antpool Technologies

Singapore-based cloud mining service Bitfufu has obtained a $100 million credit line from Antpool Technologies, intended to reinforce its bitcoin holdings Antpool Backs Bitfufu With $100 Million