'BlackRock' Android Trojan Malware Can Steal Banking Credentials, Says CERT-In

CERT-In says the malware is deadly as it has the capability to "deflect" majority of antivirus applications.

Advertisement
By Press Trust of India | Updated: 30 July 2020 15:59 IST
Highlights
  • CERT-In has issued an advisory with respect to "BlackRock" malware
  • The Android malware was first spotted in May
  • CERT-In suggests counter-measures to Android users

The "BlackRock" Android malware is capable of stealing user credentials from apps

The country's cyber security agency has issued an alert against an Android malware, dubbed "BlackRock", that has the potential to "steal" banking and other confidential data of a user. It can extract credentials and credit card information from over 300 apps such as email, e-commerce apps, social media apps, besides banking and financial apps, the CERT-In said in an advisory.

The "attack campaign" of this 'Trojan' category malware is active globally, said the Computer Emergency Response Team of India (CERT-In), the national technology arm to combat cyber-attacks and guard Indian cyberspace. The BlackRock Android malware was initially reported by ThreatFabric earlier this month, and first spotted in May.

"It is reported that a new Android malware strain dubbed 'BlackRock' equipped with data-stealing capabilities is attacking a wide range of Android applications.

Advertisement

"The malware is developed using the source code of Xerxes banking malware which itself is a variant of LokiBot Android Trojan," the advisory said.

Advertisement

The "noteworthy feature" of this malware is that its target list contains 337 applications including banking and financial applications, and also non-financial and well-known commonly used brand name apps on an Android device that focus on social, communication, networking and dating platforms, it said.

"It can steal credentials and credit card information from over 300 plus apps like email clients, e-commerce apps, virtual currency, messaging or social media apps, entertainment apps, banking and financial apps etc," the advisory said.

Advertisement

The advisory described the infection activity of the malware.

"When the malware is launched on the victim's device, it hides its icon from app drawer and then masquerades itself as a fake Google update to request accessibility service privileges."

Advertisement

"Once this privilege is granted, it becomes free to grant itself additional permissions allowing it to function further without interacting with user," it said.

Threat operators can issue a number of commands for various operations such as logging keystrokes, spamming the victims'' contact lists with text messages, setting the malware as the default SMS manager, pushing system notifications to the C2 (command and control) server, locking the victim in the device home screen and steal and hide notifications, send spam and steal SMS messages and many more such activities, the advisory said.

The malware is deadly as it has the capability to "deflect" majority of antivirus applications.

"Another feature of this Android Trojan is making use of 'Android work profiles' to control the compromised device without requiring complete admin rights and instead creating and attributing its own managed profile to gain admin privileges," it said.

The federal cyber security agency suggested some counter-measures: do not download and install applications from untrusted sources and use reputed application market only; always review the app details, number of downloads, user reviews and check "additional information" section before downloading an app from play store, use device encryption or encrypt external SD card; avoid using unsecured, unknown Wi-Fi networks among others.

Also, when it comes to downloading banking apps one should use the official and verified version and users should make sure they have a strong AI-powered mobile anti-virus installed to detect and block this kind of tricky malware, the advisory said.


Is Redmi Note 9 the perfect successor to Redmi Note 8? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. These New AI Features Are Coming to Your Updated iPhone, iPad and Mac
  2. iPhone 17 Pro Max Cosmic Orange Variant Out of Stock in the US, India: Report
  3. Samsung Galaxy Tab A11, Tab A11+ Design, Features Leaked Ahead of Launch
  4. iPhone 17 Series, iPhone Air Pre-Order Discounts Announced by Retailers in India
  5. Early Deals on PlayStation 5 and Accessories Revealed Ahead of Amazon Sale
  6. iPhone 16 Pro, iPhone 16 Pro Max Offers Listed Ahead of Flipkart Sale
  7. Oppo Find X9 Pro Chipset, AnTuTu and Geekbench Scores Revealed
  8. Google Pixel 10 Review: A Brilliant Phone We Wanted to Love
  9. Vivo V60e Price in India, Specifications Surface Ahead of Launch
  10. Amazon Sale 2025: Early Deals on Smartphones
  1. Google Search App for Windows Launched With Spotlight-Like Features
  2. Flipkart Big Billion Days Sale 2025: Discounts on iPhone 16 Pro, iPhone 16 Pro Max Listed Ahead of Sale
  3. YouTube Announces New AI-Powered Tools for Shorts Creators, Podcasters at Made on YouTube Event
  4. Xiaomi 17 Pro Design Teased Again as Smartphone Appears on Geekbench With Snapdragon 8 Elite Gen 5 SoC
  5. Moto G36 Design and Features Revealed by TENAA Listing; Likely to Feature 6,790mAh Battery, 6.72-Inch Display
  6. iPhone 17 Series, iPhone Air Pre-Order Discounts Announced by Croma, Ingram Micro India, and Vijay Sales
  7. Vivo V60e Price and Specifications Reportedly Surface Ahead of India Launch
  8. OpenAI Plans Stricter Protections for Teens, Expands Privacy for Adult Users
  9. Sony Said to Be Planning State of Play Broadcast for Next Week
  10. France Could Block Crypto Firms With MiCA Licenses Due to Enforcement Gap Concerns
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.