Xenomorph Malware Strikes At The Heart Of The US Crypto Community – Details

Share This Post

A recent discovery by security experts has revealed the existence of a malware that specifically targets Android users in the US, Canada, Italy, Portugal, Spain, and Belgium.

Known as Xenomorph, the perpetrators behind this highly advanced Android banking trojan have been consistently directing their efforts towards European users for more than a year. However, they have recently expanded their operations to include consumers of over 25 American financial institutions.

The Xenomorph has returned, and this iteration is even more lethal than ever. Now a more serious danger, it has spread to more than 100 financial and cryptocurrency apps, according to analysts.

Phishing Tactics And Malware Distribution

The current Xenomorph campaign began in mid-August, according to analysts at cybersecurity firm ThreatFabric, who have been monitoring the malware’s activity since February 2022.

The malware authors’ latest campaign involves phishing URLs that encourage users to update their Chrome browsers and download the dangerous APK. The malware is still using overlay techniques to collect data, but now it is now going after US banks and a variety of cryptocurrency apps.

ThreatFabric analysts gained access to the malware operator’s payload hosting infrastructure by taking advantage of the operator’s lax security procedures.

The malware’s Private Loader, the Windows information thieves RisePro and LummaC2, and the Android malware versions Medusa and Cabassous were among the other harmful payloads they found there.

A noteworthy characteristic of the latest iteration of Xenomorph pertains to its advanced and adaptable Automatic movement System (ATS) structure, which facilitates the automated movement of cash from a compromised device to one controlled by an attacker.

Xenomorph Goes After Banks

The ATS engine of the Xenomorph malware has several modules that enable threat actors to gain control over compromised devices and carry out a range of malicious activities.

The malware targets Chase, Amex, Ally, Citi Mobile, Citizens Bank, Bank of America, and Discover Mobile consumers. ThreatFabric researchers found new trojan samples that target Bitcoin, Binance, and Coinbase.

The Xenomorph banking virus targeted 56 European banks employing screen overlay phishing in early 2022. Google Play delivered it to over 50,000 users.

Hadoken Security: The Malware Brains

The firm behind it, “Hadoken Security,” improved the virus and released a modular, flexible version in June 2022. Xenomorph was one of the top 10 banking trojans and a Zimperium “major threat” by then.

Depending on the demographic, each Xenomorph sample has about a hundred overlays that target various banks and cryptocurrency apps.

Meanwhile, users should exercise caution when urged to upgrade their mobile browsers, as these requests are often hidden spyware.

Featured image from Bleeping Computer

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

XRP Community Gets New Rewards, Fed Rules out BTC Reserves, and More — Week in Review

XRP community gets new rewards, Fed rules out BTC reserves, Strike CEO says Trump eyeing US BTC reserve, and more in this Week in Review Week in Review Ripple’s RLUSD stablecoin debuted on

Ethereum Price Drops 12% As Spot ETFs Witness Significant Net Outflows

The Ethereum price has been a joy to watch in recent weeks after initially struggling to keep pace with other large-cap cryptocurrencies However, the past week will be a quick one to forget for the

TOP 10 Altcoins Under $0.10 to Buy in 2025!

The post TOP 10 Altcoins Under $010 to Buy in 2025! appeared first on Coinpedia Fintech News Considering to finally enter the world of the future, the right time is here as the market is highly

TOP 10 Altcoins Under $0.10 to Buy in 2025!

The post TOP 10 Altcoins Under $010 to Buy in 2025! appeared first on Coinpedia Fintech News Considering to finally enter the world of the future, the right time is here as the market is highly

Bitcoin Spot-Perpetual Price Gap Turns Negative – Bearish Signal Or Not?

The US Federal Reserve’s public consideration of reduced interest rate cuts in 2025 resulted in numerous negative effects on financial markets Aside from a 17% price loss for Bitcoin, data from

Angel Investor: Multichain a Stopgap, Future Lies in Advanced Protocols

Constantine Zaitsev, CEO of DRPC, believes multichain solutions are a temporary fix and future advancements like modular blockchains hold promise for a more streamlined approach to blockchain