SMS stealing apps uploaded to Google Play by Carberp banking malware gang
The apps were designed to steal mobile transaction authentication numbers from Russian online banking users, Kaspersky Lab says
IDG News Service - Several malicious Android apps designed to steal mobile transaction authentication numbers (mTANs) sent by banks to their customers over SMS (Short Message Service) were found on Google Play by researchers from antivirus vendor Kaspersky Lab.
The apps were created by a gang that uses a variant of the Carberp banking malware to target the customers of several Russian banks, Denis Maslennikov, a senior malware analyst at Kaspersky, said Friday in a blog post.
Many banks use mTANs as a security mechanism to prevent cybercriminals from transferring money from compromised online banking accounts. When a transaction is initiated from an online banking account, the bank sends an unique code called an mTAN via SMS to the account owner's phone number. The account owner has to input that code back into the online banking website in order for the transaction to be authorized.
In order to defeat this type of defense, cybercriminals created malicious mobile apps that automatically hide SMS messages received from numbers associated with the targeted banks and silently upload the messages back to their servers. Victims are tricked into downloading and installing these apps on their phones via rogue messages displayed when visiting their bank's website from an infected computer.
SMS stealing apps have previously been used together with the Zeus and SpyEye banking Trojan programs and are known as Zeus-in-the-Mobile (ZitMo) and SpyEye-in-the-Mobile (SpitMo) components. However, this is the first time a rogue mobile component designed specifically for the Carberp malware has been found, Maslennikov said.
Unlike Zeus and SpyEye, the Carberp Trojan program is primarily used to target online banking customers from Russia and other Russian-speaking countries like Ukraine, Belarus or Kazakhstan.
According to a report in July from antivirus vendor ESET, Russian authorities arrested the people behind the three largest Carberp operations. However, the malware continues to be used by other gangs and is being sold on the underground market for prices between $5,000 and $40,000, depending on the version and its features.
"This is the first time we've seen mobile malicious components from a Carberp gang," Aleksandr Matrosov, senior malware researcher at antivirus vendor ESET, said Friday via email. "Mobile components are used only by one Carberp group, but we can't disclose more details at the present."
The new Carberp-in-the-Mobile (CitMo) apps found on Google Play masqueraded as mobile applications from Sberbank and Alfa-Bank, two of Russia's largest banks, and VKontakte, the most popular online social networking service in Russia, Maslennikov said. Kaspersky contacted Google on Wednesday and all CitMo variants were deleted from the market by Thursday, he said.
However, the fact that cybercriminals managed to upload these apps to Google Play in the first place raises questions about the efficiency of the app market's anti-malware defenses, such as the Bouncer anti-malware scanner announced by Google earlier this year.
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Jyske Bank extends brand message to more than one million visitors a month
- IBM WebSphere Portal software helps bank offer a clearly differentiated digital experience
- The Big Data Opportunity for HR and Finance
- If CEOs, CFOs, CIOs, and CHROs want to drive their businesses forward, they will need to quickly recognize the enormous value of big...
- Agility & Scalability for Oracle EBS R12 and RAC on VMware vSphere 5
- This white paper outlines extensive performance and scalability testing of Oracle EBS applications on a Vblock™ Systems with vSphere 5.
- Oracle and VCE: The Next Step in Integrated Computing Platforms
- In this ESG Lab review you will learn how a VCE system driven by Oracle, delivers the perfect blend of high performance and...
- Migrate Oracle Apps from RISC/UNIX to Virtualized x86
- Ready to move Oracle to a virtualized environment? This brief explains how true converged infrastructure can help you migrate from a RISC/UNIX environment... All Financial IT White Papers
- Keep Servers Up and Running and Attackers in the Dark An SSL/TLS handshake requires at least 10 times more processing power on a server than on the client. SSL renegotiation attacks can readily...
- On Demand: Mastering the Art of Mobile Content Management Mobile device usage in the enterprise has skyrocketed, and it continues to escalate. IT must answer to users who demand access to their...
- DevOps with PureApplication System: Reduce cost and speed delivery with an integrated IBM Cloud solution Join this webcast to hear what ING Netherlands has been able to achieve while deploying DevOps tools from IBM Rational. An ING executive...
- NSS Labs & Cisco Present: Evaluating Leading Breach Detection Systems Today's constantly evolving advanced malware and APTs can evade point-in-time defenses to penetrate networks. Security professionals must evolve their strategy in lockstep to...
- Will the Real Endpoint Threat Detection and Response Please Stand Up? This webinar explores new technologies & process for protecting endpoints from advanced attackers as well as the innovations that are pushing the envelope...
- All Financial IT Webcasts