Android Malware DroidBot: Banking and Crypto Apps Targeted via Accessibility Services Abuse

ISGroup Cybersecurity

DroidBot is a new Android banking malware first identified in June 2024. Operating as malware-as-a-service (MaaS), it targets over 77 banking and cryptocurrency apps across Europe, showing signs of expansion into other geographic areas. The malware exploits Android Accessibility Services, allowing attackers to steal credentials, manipulate the device, and control it remotely.

Date2024-12-05 09:49:13
Information
  • Active Exploitation

Technical Summary

DroidBot is a sophisticated Android malware distributed via MaaS platforms at a cost of $3,000/month. It is used by at least 17 affiliate threat actor groups, each of which customizes payloads to target specific applications and regions. The malware often disguises itself as legitimate apps such as Google Chrome, Google Play, or Android Security. Its main features include:

  • Keylogging: Intercepts all keystrokes typed by the user.
  • Overlaying: Displays fake login screens over legitimate banking and crypto app interfaces to harvest credentials.
  • SMS Interception: Intercepts SMS messages, particularly those containing one-time passwords (OTP).
  • Remote Control: Includes a VNC (Virtual Network Computing) module that allows attackers to manipulate the device remotely.

The use of Accessibility Services by DroidBot allows it to monitor user activity, simulate interactions, and conceal its presence by obscuring the device screen.

Recommendations

To protect against DroidBot:

  1. App installation best practices:

    • Download apps only from trusted sources, such as Google Play.
    • Verify app developers and carefully analyze reviews before downloading.
  2. Permission awareness:

    • Deny unnecessary or suspicious permission requests, particularly access to Accessibility Services.
    • Re-evaluate permissions granted to installed apps via device settings.
  3. Enable security features:

    • Enable Google Play Protect to scan for and block malicious apps.
    • Keep the Android operating system and all apps updated to patch potential vulnerabilities.
  4. Monitoring and response:

    • Watch for signs of unauthorized activity, such as apps requesting new permissions or anomalous device behavior.
    • Immediately uninstall suspicious apps and reset credentials for potentially compromised accounts.
  5. Apply enterprise controls (for organizations):

    • Use Mobile Device Management (MDM) solutions to restrict app installation.
    • Train employees on the risks of phishing and mobile malware.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert