Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms

Malware worm
(Image credit: Shutterstock)

  • Phishing websites impersonate trusted brands to deceive users
  • Advanced obfuscation techniques evade traditional security measures
  • Real-time detection is crucial for mobile security defence, experts warn

A coordinated mobile malware campaign has been found targeting financial institutions worldwide, experts have warned.

Zimperium's zLabs research team found the campaign leveraged two dangerous malware families, Gigabud and Spynote, to compromise mobile devices and target banking apps.

More than 50 financial mobile apps, including 40 banks and 10 cryptocurrency platforms, have been targeted in this sophisticated malware campaign.

Global malware campaign

While Gigabud primarily focuses on stealing banking app credentials through phishing websites and malicious apps, Spynote allows attackers to take full control of infected devices, and is capable of stealing data, recording media, tracking locations, and remotely controlling devices.

Domains distributing Gigabud were also found to be spreading Spynote, indicating a coordinated, large-scale effort to exploit mobile device vulnerabilities. Together, these malware strains pose a serious risk to both personal and corporate data, signalling a more complex mobile cyber threat.

The campaign’s reach is global, affecting financial institutions in several countries, as Zimperium discovered 11 command-and-control servers and 79 phishing websites impersonating brands such as Ethiopian Airlines, Vietnamese financial platforms, popular ecommerce sites, and even government services.

The attackers have specifically targeted mobile banking apps to gain unauthorized access to sensitive information, including login credentials, banking details, and transaction histories.

The Gigabud - Spynote campaign makes use of advanced obfuscation techniques to evade traditional security measures. The malware is packed using Virbox, a tool designed to conceal malicious code, making it harder for traditional detection methods to identify and analyze the malware.

Though the campaign primarily targets consumer-focused mobile banking apps, the level of access that Gigabud and Spynote achieve raises concerns for corporate security. Many users have both personal and work-related applications on the same mobile devices, so if a personal device is compromised, sensitive corporate applications and data, including credentials and two-factor authentication methods, could also be at risk.

Given the global scale of this campaign and the heavy focus on financial apps, Zimperium urges both consumers and organizations to take immediate steps to protect themselves.

Companies need to ensure that they have real-time, on-device mobile security measures capable of detecting and stopping advanced threats, and need to educate employees about the risks of downloading apps from unofficial sources, clicking on suspicious links, and granting unnecessary permissions is crucial to mitigating the risks of mobile malware.

“The connection between Gigabud and Spynote demonstrates the growing complexity of mobile malware attacks. Our latest research highlights the critical importance of real-time, on-device detection to protect against these rapidly evolving threats," noted Nico Chiaraviglio, Chief Scientist at Zimperium.

You may also like

Efosa Udinmwen
Freelance Journalist

Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master's and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity. Upon joining TechRadar Pro, in addition to privacy and technology policy, he is also focused on B2B security products. Efosa can be contacted at this email: udinmwenefosa@gmail.com

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
mobile phone
Forget phishing, now "mishing" is the new security threat to worry about
Close up of a business person using a smartphone.
Watch out, malicious PDF files are being used again in phishing attacks
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
App stores are increasingly becoming a major security worry
Fraud
Hackers are tricking victims into scam-yourself attacks with fake tutorials, CAPTCHAs, and updates
Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why
Nintendo x Seattle Mariners partnership
The Nintendo Switch 2 logo will be featured on the Seattle Mariners' baseball jerseys this season
Apple iPhone 16 Pro Max Review
Siri's chances to beat ChatGPT just got a whole lot better