SharkBot Android Banking Trojan: A New Era of ATS Attacks on Mobile

ISGroup Cybersecurity

SharkBot, discovered in October 2021 by the Cleafy Threat Intelligence team, is an advanced Android banking trojan that targets banks and cryptocurrency services in the United Kingdom, Italy, and the United States. This malware represents a new generation of mobile threats with innovative capabilities, particularly by leveraging Automatic Transfer System (ATS) attacks. These attacks bypass traditional authentication mechanisms, allowing attackers to amplify fraudulent activities without direct user interaction.

Date2024-12-06 15:28:40
Information
  • Trending

Technical Summary

SharkBot uses Android Accessibility Services to perform its malicious activities, including:

  • ATS Attacks: Automatic filling of fields in legitimate banking apps to perform unauthorized money transfers.
  • Overlay Attacks: Imitating app login screens to steal credentials and credit card data.
  • Keylogging: Monitoring and recording sensitive user inputs.
  • SMS Interception: Capturing SMS-based two-factor authentication codes.
  • Full Remote Control: Simulating gestures and clicks to manipulate the device.

Key Features and Techniques:

  1. Analysis Evasion:

    • String obfuscation to hide commands and C2 details.
    • Emulator detection to bypass sandboxes.
    • Encrypted communications via Base64 encoding and a Domain Generation Algorithm (DGA).
  2. Advanced Permission Abuse:

    • Exploits REQUEST_IGNORE_BATTERY_OPTIMIZATIONS to maintain connection with C2 servers.
    • Uses Accessibility Services to manipulate settings and prevent uninstallation.
  3. Modular Design:

    • Downloads an external .jar file containing ATS functionalities from the C2.

Indicators of Compromise (IOCs):

  • App Names: Media Player HD.
  • Package Name: com.pycdvgljmfgh3hgp8jo72giu.omflsx1q2g.
  • C2 Domains: sharkedtest1[.]xyz, sharkedtestuk[.]xyz.
  • MD5 Hash: f7dfd4eb1b1c6ba338d56761b3975618.

Recommendations

For Organizations (Banks, Crypto Platforms):

  1. Behavioral Analysis: Implement advanced detection mechanisms to identify anomalies in user actions (e.g., ATS attacks).
  2. Zero Trust Policies: Treat all transactions, even from trusted devices, with additional scrutiny.
  3. Monitoring and Alerts: Actively monitor for unexpected overlays and accessibility events within your apps.
  4. Awareness Campaigns: Educate users on emerging threats like SharkBot and the risks associated with granting excessive permissions.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert