Researchers found an Android malware ‘BlackRock’ that dropped its icon when it initially launched itself on a mobile device. At the time, it pretended as a Google update in a trial to get access to a user’s Accessibility Service.
This trojan will steal both login credentials, the username as well as password, as both are available, but also assist the victim in providing all payment card details if the apps support financial activities.
When they get access to these opportunities, the malware allowed itself additional grants that allowed it to interact with its command-and-control (C&C) server and to implement all the overlay attacks.
The BlackRock malware has added some additional features, particularly ones that support to steal passwords and credit card data. But, the BlackRock works like most Android trading trojans, though, besides it targets more apps than most of its forerunners.
BlackRock malware manages data by exploiting Android’s Accessibility Service events while launching for the first time requesting the users’ permissions under cover of fake Google updates.
It is available in the Play Store and is infiltrating devices by offering as a fake Google Update on third-party stores. As all the Android malware groups usually have found ways to circumvent Google’s app review method in the past.
The BlackRock malware from root works like older Android malware and always practice tried and tested methods to show the overlays and administrator data.
According to the Threatfabric report, BlackRock is competent in keylogging, conferring permissions, SMS harvesting and sending, screen locking, device data collection, notification group, AV detection, hide its app icon, and also limit its removal.
The malware is initially launched on the device, and it starts by covering its icon from the app drawer, making it undetectable to the end-user. In the second step, it urges the victim for the Accessibility Service privileges.
Once the user allows the demanded Accessibility Service privilege, BlackRock begins by giving itself some additional approvals. Those additional approvals are needed for the bot to function entirely without having to communicate with any victims further. Once they are done, the bot is practical and able to receive commands from the C2 server and perform the overlay attacks.
Apart from this, the BlackRock malware is currently serving in the US, Europe, Australia, and Canada via shopping, communication, and business apps.
The commands that are involved in this vulnerability are as follow:-
The features of BlackRock malware are present in a set, enabling it to work under the radar and actively collect all the required personal information; and here are they:-
The attack of BlackRock malware is quite different from other malware due to its array of apps they target, which go behind the mobile banking apps that are regularly get targeted.
The security experts strongly recommended a few security measures to the users to protect themselves from these type of vulnerabilities, and here they are:-
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…