Description
The notorious banking trojan SharkBot has resurfaced once again on the Google Play Store, disguised behind Antivirus and Cleaner applications, dropping a new version of the malware.
Summary
In April of 2022, researchers have found the Sharkbot malware pretending to be Antivirus and cleaners solutions on six applications in the Google Play store. These are Atom Clean-Booster Antivirus, Antivirus Super Cleaner, Alpha Antivirus Cleaner, Powerful Cleaner Antivirus and Center Security Antivirus (two applications with the same name from the same developer account). These applications were removed from the Google Play store. However, before it was removed, it was downloaded and installed approximately fifteen thousand times. What was also interesting, is that the malware displayed a geofencing feature which allows it to identify and attack specific targets in countries excluding China, India, Romania, Russia, Ukraine and Belarus.
Fast forward to August of 2022, the Sharkbot malware was seen by researchers, disguised as two new Antivirus solutions, Kylhavy Mobile Security and Mister Phone Cleaner,dropping a newer version of the malware, version 2.25. Both applications have seen over sixty thousand installations between them, targeting users in Spain, Australia, Poland, Germany, the U.S., and Austria. Sharkbot aims at stealing credentials and banking information. However, the new version includes an updated command and control (C2) domain communication, new domain generation algorithm (DGA) and fully refactored code. A newly introduced function to the malware is the ability to steal session cookies when victims log in to their bank accounts.
How it works
Before installation of the malware, the Sharkbot dropper checks the devices SIM provider country code to see if the device is in the list of the targeted countries. The dropper relies on abusing the Androids accessibility permissions in order to install the malware. The dropper does so by making a request to the C2 server which then provides a URL to download the malware onto the device. The dropper abuses the access permissions again to automatically install the malware. However, the newer version of Sharkbot uses a different approach by making a request to the C2 server and receives the APK file of the malware. It does so by using a POST request body with a JSON object containing the malware and the body of the request is encrypted using RC4 and a hard coded key. The malware is installed by prompting the user to install the APK file as an update to the fake Antivirus software. Once installed, the malware via the Antivirus will ask the user to grant it accessibility permissions.
The features of the Sharkbot malware includes overlay attacks where it steals credentials by providing a WebView of a fake login whenever a banking application is opened; it can steal credentials by logging accessibility events such as changes to text fields and buttons clicked; it has the ability to intercept SMS messages on the device and it can obtain full remote control of a device via Accessibility Services. The new feature in 2.25 includes cookie stealing which allows the malware to steal the session cookies when a victim logs into a banking application and these cookies can be used to replicate the session in a WebView. All captured information is exfiltrated to the malwares C2 server.
Indicators of Compromise
The following hashes and strings correspond to files linked to the Sharkbot malware:
Sharkbot Google Play links:
Sharkbot C2 domains:
hxxp://mefika.me/
Sharkbot DGA C2 domains:
Sharkbot 2.25
Remediation
To circumvent this type of malware, users are advised to follow the steps below:
The Guyana National CIRT recommends that users and administrators review this alert and make changes where necessary.
PDF Download: Android_devices_infiltrated_by_sharkbot_malware.pdf
References
Lakshmanan, R (2022, September 5). Fake Antivirus and Cleaner Apps Caught Installing SharkBot Android Banking Trojan. Retrieved from The Hacker News..
https://thehackernews.com/2022/09/fake-antivirus-and-cleaner-apps-caught.html
Segura, A. and Stokkel, M. Sharkbot is back in Google Play. Retrieved from Fox-It.
https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play/
Lakshmanan, R (2022, April 7). SharkBot Banking Trojan Resurfaces On Google Play Store Hidden Behind 7 New Apps. Retrieved from The Hacker News.
https://thehackernews.com/2022/04/sharkbot-banking-trojan-resurfaces-on.html
Tech Desk (2022, September 6, 2022). The return of the SharkBot Malware: Heres how to protect yourself. Retrieved from The Indian Express.
https://indianexpress.com/article/technology/crypto/the-return-of-the-sharkbot-malware-heres-how-to-protect-yourself-8133847/