Source code for data-stealing Android app leaks

Share this article:

Mobile malware, which often disguises itself as an Android "security app," may threaten a greater number of users now that its source code has leaked.

On Thursday, Daniel Cohen, the head of knowledge delivery and business development for RSA's FraudAction Group, warned users via a company blog about the threat.

According to Cohen, the iBanking mobile bot was introduced to the underground market late last year for $5,000. At the time, the malware was spread through HTML injection attacks on banking websites, and through social engineering ruses that tricked users into downloading the “security app.”

Cohen warns now, however, that the control panel for the source code has leaked, giving more saboteurs to the opportunity to wield the malware to target users' information.

“Apart from the server-side source-code, the leaked files also include a builder…that can unpack the existing iBanking APK file and re-pack it with different configurations, essentially providing fraudsters with the means to create their own unique application,” Cohen wrote.

In addition to sniffing text messages, the malicious app also has features that allow it to redirect users' calls, record their conversations using the device's mic, and steal other sensitive data, like contacts, the blog post said.

“The malware is an example of the ongoing developments in the mobile malware space and we are now seeing the next generation of malicious apps being developed and commercialized in the underground, boasting web-based control panels and packing more data-stealing features,” Cohen said.

RSA learned of the leaked source code via an online post this month in an underground forum (screen shot here).

Share this article:

Sign up to our newsletters

More in News

Latest Citadel trick allows RDP access after malware's removal

Latest Citadel trick allows RDP access after malware's ...

Trusteer, an IBM company, said the new Citadel configuration was detected this month.

Cryptoblocker variant emerges, encryption differs from CryptoLocker

Trend Micro has detected a variant of CryptoLocker in the wild that relies on the advanced encryption standard.

Jimmy John's sandwich chain investigating possible breach

Some financial institutions have indicated that credit cards recently used at Jimmy John's locations have been used to make fraudulent purchases.