MysteryBot Android Malware Combines Banking Trojan, Ransomware, and Keylogger

Advertisement
By Sumit Chakraborty | Updated: 18 June 2018 17:42 IST
Highlights
  • MysteryBot combines a banking trojan, keylogger, and ransomware
  • MysteryBot, runs on the same command and control server as the LokiBot
  • The malware targets devices running on Android 7.x or 8.x

A new Android malware that combines a banking trojan, a ransomware, and a keylogger has been discovered. Security researchers at ThreatFabric have found the new type of malware that packs all the three threats in one package, and it was earlier thought to be an updated version of LokiBot. But, since the new malware comes with various new features researchers have labelled it as a new form of malware, called MysteryBot. Notably, the MysterBot targets smartphones running Android 7.x or Android 8.x.

As per a blog post by ThreatFabric, the MysteryBot and LokiBot Android malware are "both running on the same C&C server." Since they share the same command and control server, it means that there could be a strong link between the two forms of malware, and they could have been developed by the same attacker. What makes the MysteryBot lethal is its capabilities to take control over users' phone. Apart from having Android banking trojan functionalities, the malware exhibits overlay, keylogging, and ransomware functionalities.

Advertisement

The malware also contains commands for stealing emails and remotely starting apps. However, such tools are not active yet, meaning the malware is still in its development phase. MysteryBot is reportedly able to target the latest Android versions - Nougat and Oreo. Researchers say that the malware uses overlay screens designed to look like real bank site, but are run by attackers.

The researchers also said that a new technique abuses a service permission called 'Package Usage Stats' that is accessible through the Accessibility Service permission in Android phones. This method allows the trojan to enable and abuse any other permission without the user's consent.

Advertisement

The MysteryBot also contains a keylogger. But researchers said that none of the already-known keylogging techniques was used. Instead, the malware calculates the location for each row and places a view over each key.

"This view has a width and height of zero pixels and due to the "FLAG_SECURE" setting used, the views are not visible in screenshots. Each view is then paired to a specific key in such a way that it can register the keys that have been pressed which are then saved for further use," said researchers. However, they added, "The code for this the keylogger seems to still be under development as there is no method yet to send the logs to the C2 server."

Advertisement

The malware also has inbuilt ransomware to individually encrypt all files in the external storage directory, including every subdirectory, after which the original files are deleted. "The encryption process puts each file in an individual ZIP archive that is password protected, the password is the same for all ZIP archives and is generated during runtime. When the encryption process is completed, the user is greeted with a dialog accusing the victim of having watched pornographic material," said researchers.

From the looks of it, MysteryBot is not quite widespread as it is still under development. However, you should be aware of any apps that ask for an excessive number of permissions, and always install apps from trusted sources, such as Google Play.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: MysteryBot, Malware
Advertisement
Popular Mobile Brands
  1. These OnePlus Smartphones Could Receive the ColorOS 17 Update in India
  2. Redmi Note 17 Pro Max Listed on NBTC Website Ahead of Imminent Launch
  1. Offline UPI Payments With NFC Support Could Launch in India Soon
  2. Samsung Galaxy S26 Ultra's Privacy Display Feature Gets a Major Upgrade in One UI 9 Beta
  3. OnePlus N6x Design, Colour Options Teased in New Marketing Material Ahead of Imminent Launch in India
  4. OnePlus 11, Nord 4, and Newer Models Tipped to Receive the Android 17-Based ColorOS 17 Update in India
  5. Redmi Note 17 Pro Max Appears on Thailand's NBTC Certification Database, Might Launch Soon
  6. Apple’s First Foldable iPhone Reportedly Appears in iOS 27 Beta Code With a Multi-Battery Setup
  7. X for Android App Undergoes Major Design Overhaul, Enhanced Performance and Reliability
  8. Samsung Galaxy Buds Able to Reportedly Skip Galaxy Unpacked Launch; Could Debut in October
  9. Dell Alienware 16X Aurora, Alienware 16 Area-51 and Alienware 18 Area-51 Launched in India: Price, Specifications
  10. Samsung Galaxy A55, Galaxy A35 One UI 9 Test Builds Reportedly Spotted Ahead of Android 17 Rollout
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.