Xenomorph Malware Strikes At The Heart Of The US Crypto Community – Details

Share This Post

A recent discovery by security experts has revealed the existence of a malware that specifically targets Android users in the US, Canada, Italy, Portugal, Spain, and Belgium.

Known as Xenomorph, the perpetrators behind this highly advanced Android banking trojan have been consistently directing their efforts towards European users for more than a year. However, they have recently expanded their operations to include consumers of over 25 American financial institutions.

The Xenomorph has returned, and this iteration is even more lethal than ever. Now a more serious danger, it has spread to more than 100 financial and cryptocurrency apps, according to analysts.

Phishing Tactics And Malware Distribution

The current Xenomorph campaign began in mid-August, according to analysts at cybersecurity firm ThreatFabric, who have been monitoring the malware’s activity since February 2022.

The malware authors’ latest campaign involves phishing URLs that encourage users to update their Chrome browsers and download the dangerous APK. The malware is still using overlay techniques to collect data, but now it is now going after US banks and a variety of cryptocurrency apps.

ThreatFabric analysts gained access to the malware operator’s payload hosting infrastructure by taking advantage of the operator’s lax security procedures.

The malware’s Private Loader, the Windows information thieves RisePro and LummaC2, and the Android malware versions Medusa and Cabassous were among the other harmful payloads they found there.

A noteworthy characteristic of the latest iteration of Xenomorph pertains to its advanced and adaptable Automatic movement System (ATS) structure, which facilitates the automated movement of cash from a compromised device to one controlled by an attacker.

Xenomorph Goes After Banks

The ATS engine of the Xenomorph malware has several modules that enable threat actors to gain control over compromised devices and carry out a range of malicious activities.

The malware targets Chase, Amex, Ally, Citi Mobile, Citizens Bank, Bank of America, and Discover Mobile consumers. ThreatFabric researchers found new trojan samples that target Bitcoin, Binance, and Coinbase.

The Xenomorph banking virus targeted 56 European banks employing screen overlay phishing in early 2022. Google Play delivered it to over 50,000 users.

Hadoken Security: The Malware Brains

The firm behind it, “Hadoken Security,” improved the virus and released a modular, flexible version in June 2022. Xenomorph was one of the top 10 banking trojans and a Zimperium “major threat” by then.

Depending on the demographic, each Xenomorph sample has about a hundred overlays that target various banks and cryptocurrency apps.

Meanwhile, users should exercise caution when urged to upgrade their mobile browsers, as these requests are often hidden spyware.

Featured image from Bleeping Computer

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Bitcoin Cost Basis Distribution Reveals Strong Demand At $97K – Can BTC Hold?

Bitcoin has had a whirlwind few days, hitting an all-time high (ATH) last Tuesday before tumbling into a sharp 15% correction This period of heightened volatility has left investors divided, with

XRP Price Prediction For December 22

The post XRP Price Prediction For December 22 appeared first on Coinpedia Fintech News Ripple’s XRP is down by more than six percent and is trading at $222 level at the time of writing XRP’s

Permianchain and Vertical Data Team Up to Bring GPU-as-a-Service to MENA

Permianchain, a subsidiary of UAE investment firm Hodler Investments, partnered with Vertical Data to offer modular and portable data center solutions using Vertical Data’s GPU-as-a-service

Targets To Watch As Dogecoin Price Recovers For A Play Toward $1

A crypto analyst has shared a Dogecoin price chart over a daily time frame, highlighting key price levels to watch out for as the meme coin attempts to recover towards the coveted $1 milestone

The Solana Layer 2 Revolution: Why Solaxy’s $SOLX Could Be The Next 100x Token

This is the year of memecoins Popular meme coins like DOGE, BONK, Pepe and FLOKI have managed to garner a lot of attention Even newer memecoins such as Wall Street Pepe and Flockerz have also left a

Analyst Says Bitcoin Price Peak Lies Above $225,000, The Timeline Will Shock You

As of December 21, 2024, the Bitcoin price is trading at around $98,600, reflecting a 34% increase from its previous close This rise is part of a broader trend marked by substantial price