SharkBot, discovered in October 2021 by the Cleafy Threat Intelligence team, is an advanced Android banking trojan that targets banks and cryptocurrency services in the United Kingdom, Italy, and the United States. This malware represents a new generation of mobile threats with innovative capabilities, particularly by leveraging Automatic Transfer System (ATS) attacks. These attacks bypass traditional authentication mechanisms, allowing attackers to amplify fraudulent activities without direct user interaction.
| Date | 2024-12-06 15:28:40 |
| Information |
|
Technical Summary
SharkBot uses Android Accessibility Services to perform its malicious activities, including:
- ATS Attacks: Automatic filling of fields in legitimate banking apps to perform unauthorized money transfers.
- Overlay Attacks: Imitating app login screens to steal credentials and credit card data.
- Keylogging: Monitoring and recording sensitive user inputs.
- SMS Interception: Capturing SMS-based two-factor authentication codes.
- Full Remote Control: Simulating gestures and clicks to manipulate the device.
Key Features and Techniques:
Analysis Evasion:
- String obfuscation to hide commands and C2 details.
- Emulator detection to bypass sandboxes.
- Encrypted communications via Base64 encoding and a Domain Generation Algorithm (DGA).
Advanced Permission Abuse:
- Exploits
REQUEST_IGNORE_BATTERY_OPTIMIZATIONSto maintain connection with C2 servers. - Uses Accessibility Services to manipulate settings and prevent uninstallation.
- Exploits
Modular Design:
- Downloads an external
.jarfile containing ATS functionalities from the C2.
- Downloads an external
Indicators of Compromise (IOCs):
- App Names: Media Player HD.
- Package Name:
com.pycdvgljmfgh3hgp8jo72giu.omflsx1q2g. - C2 Domains:
sharkedtest1[.]xyz,sharkedtestuk[.]xyz. - MD5 Hash:
f7dfd4eb1b1c6ba338d56761b3975618.
Recommendations
For Organizations (Banks, Crypto Platforms):
- Behavioral Analysis: Implement advanced detection mechanisms to identify anomalies in user actions (e.g., ATS attacks).
- Zero Trust Policies: Treat all transactions, even from trusted devices, with additional scrutiny.
- Monitoring and Alerts: Actively monitor for unexpected overlays and accessibility events within your apps.
- Awareness Campaigns: Educate users on emerging threats like SharkBot and the risks associated with granting excessive permissions.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
