This malware disguises itself as a banking app to steal info from Android devices

Android Logo
(Image credit: Google)

Mobile banking customers in Brazil are once again being targeted with malware that can take over their devices, exfiltrate sensitive data and ultimately perform wire fraud.

This is according to a new report from cybersecurity researchers ThreatFabric, who recently spotted the campaign and wrote a technical analysis as a warning. As per the researchers, threat actors known as DukeEugene were sending out phishing emails, in which they tricked the recipients into downloading a dropper for Android, called Rocinante.

This dropper, usually impersonating banking apps and telecommunications firms such as Itaú Shop, Santander, Bradesco Prime, or Correios Celular, asks for permissions upon installation, including the dreaded Accessibility Service. Generally speaking, Accessibility Service permissions are reserved for system apps only, and if a commercial app asks for them, it’s usually a red flag signaling potential malware.

Abusing Accessibility Services

If the victim grants these permissions, they can expect to lose sensitive data, and give the attackers control over their mobile device, since in many cases the malware can serve fake bank login pages:

"This malware family is capable of performing keylogging using the Accessibility Service, and is also able to steal PII from its victims using phishing screens posing as different banks," ThreatFabric said in its report. "Finally, it can use all this exfiltrated information to perform device takeover (DTO) of the device, by leveraging the accessibility service privileges to achieve full remote access on the infected device."

The stolen data gets exfiltrated to a Telegram bot, the researchers further explained, where it’s served to the attackers in plaintext, ready to be used.

"The bot extracts the useful PII obtained using the bogus login pages posing as the target banks. It then publishes this information, formatted, into a chat that criminals have access to," ThreatFabric said. "The information slightly changes based on which fake login page was used to obtain it, and includes device information such as model and telephone number, CPF number, password, or account number."

A Google spokesperson provided TechRadar Pro with a statement on the situation: "Based on our current detection, no apps containing this malware are found on Google Play. All Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play."

"Android users in Brazil are also protected by the pilot of enhanced fraud protection with Google Play Protect," the statement concluded.

Via The Hacker News

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
mobile phone
Popular Android financial help app is actually dangerous malware
Android phone malware
This nasty Android malware is posing as the Telegram Premium app
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound