SMS stealing apps uploaded to Google Play by Carberp banking malware gang
The apps were designed to steal mobile transaction authentication numbers from Russian online banking users, Kaspersky Lab says
IDG News Service - Several malicious Android apps designed to steal mobile transaction authentication numbers (mTANs) sent by banks to their customers over SMS (Short Message Service) were found on Google Play by researchers from antivirus vendor Kaspersky Lab.
The apps were created by a gang that uses a variant of the Carberp banking malware to target the customers of several Russian banks, Denis Maslennikov, a senior malware analyst at Kaspersky, said Friday in a blog post.
Many banks use mTANs as a security mechanism to prevent cybercriminals from transferring money from compromised online banking accounts. When a transaction is initiated from an online banking account, the bank sends an unique code called an mTAN via SMS to the account owner's phone number. The account owner has to input that code back into the online banking website in order for the transaction to be authorized.
In order to defeat this type of defense, cybercriminals created malicious mobile apps that automatically hide SMS messages received from numbers associated with the targeted banks and silently upload the messages back to their servers. Victims are tricked into downloading and installing these apps on their phones via rogue messages displayed when visiting their bank's website from an infected computer.
SMS stealing apps have previously been used together with the Zeus and SpyEye banking Trojan programs and are known as Zeus-in-the-Mobile (ZitMo) and SpyEye-in-the-Mobile (SpitMo) components. However, this is the first time a rogue mobile component designed specifically for the Carberp malware has been found, Maslennikov said.
Unlike Zeus and SpyEye, the Carberp Trojan program is primarily used to target online banking customers from Russia and other Russian-speaking countries like Ukraine, Belarus or Kazakhstan.
According to a report in July from antivirus vendor ESET, Russian authorities arrested the people behind the three largest Carberp operations. However, the malware continues to be used by other gangs and is being sold on the underground market for prices between $5,000 and $40,000, depending on the version and its features.
"This is the first time we've seen mobile malicious components from a Carberp gang," Aleksandr Matrosov, senior malware researcher at antivirus vendor ESET, said Friday via email. "Mobile components are used only by one Carberp group, but we can't disclose more details at the present."
The new Carberp-in-the-Mobile (CitMo) apps found on Google Play masqueraded as mobile applications from Sberbank and Alfa-Bank, two of Russia's largest banks, and VKontakte, the most popular online social networking service in Russia, Maslennikov said. Kaspersky contacted Google on Wednesday and all CitMo variants were deleted from the market by Thursday, he said.
However, the fact that cybercriminals managed to upload these apps to Google Play in the first place raises questions about the efficiency of the app market's anti-malware defenses, such as the Bouncer anti-malware scanner announced by Google earlier this year.
Flashback to the late 1960s, when this pilot fish has just gotten a job in a bank's data processing department -- and one day his new boss tells him to grab a disk pack and run for a cab.
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- The Big Data Opportunity for HR and Finance
- If CEOs, CFOs, CIOs, and CHROs want to drive their businesses forward, they will need to quickly recognize the enormous value of big...
- The Business Value of Continuous Delivery
- Download this whitepaper to learn more about the business value of Continuous Delivery and see why it could be a game changer for...
- Ten Factors Shaping the Future of Application Delivery
- Download this research report conducted by Enterprise Management Associates (EMA) to learn how those that are seeking to accelerate application delivery are leveraging...
- Software Asset Management: Ensuring Today's Assets
- Today's trends like BYOD and SaaS are new and exciting in terms of how they will help make our jobs more productive but...
- Trends Shaping Software Management: 2014
- Most IT executives recognize the relationship between mobile computing and worker productivity, and have long issued notebook computers and other mobile devices to... All Financial IT White Papers
- On-demand webinar - 7 Keys to Service Catalog Implementation Success Watch this webinar to learn 7 crucial keys to make your service catalog a success!
- Transform Your IT Service Management Watch this webinar, to learn how EasyVista can increase IT productivity & efficiency and deliver streamlined & integrated IT Service & Asset Mgmt.
- IBM FlashSystem V840: Leveraging Software-Defined Flash to Drive Your Business With end-to-end, tightly integrated functionality and super-fast flash technology, products like IBM FlashSystem V840 Enterprise Performance Solution empower businesses to leverage the efficiency...
- Leveraging Flash Storage to Accelerate Oracle Real Application Clusters Join this webinar to understand the latest solid-state storage trends, the specific applications driving solid-state storage deployments and the benefits of deploying the...
- Top 4 Digital Signage Fails Join RMG Networks for a look at four of the most common reasons digital signage fails in corporate businesses. Learn about strategies to...
- All Financial IT Webcasts