MysteryBot Android Malware Combines Banking Trojan, Ransomware, and Keylogger

Advertisement
By Sumit Chakraborty | Updated: 18 June 2018 17:42 IST
Highlights
  • MysteryBot combines a banking trojan, keylogger, and ransomware
  • MysteryBot, runs on the same command and control server as the LokiBot
  • The malware targets devices running on Android 7.x or 8.x
MysteryBot Android Malware Combines Banking Trojan, Ransomware, and Keylogger

A new Android malware that combines a banking trojan, a ransomware, and a keylogger has been discovered. Security researchers at ThreatFabric have found the new type of malware that packs all the three threats in one package, and it was earlier thought to be an updated version of LokiBot. But, since the new malware comes with various new features researchers have labelled it as a new form of malware, called MysteryBot. Notably, the MysterBot targets smartphones running Android 7.x or Android 8.x.

As per a blog post by ThreatFabric, the MysteryBot and LokiBot Android malware are "both running on the same C&C server." Since they share the same command and control server, it means that there could be a strong link between the two forms of malware, and they could have been developed by the same attacker. What makes the MysteryBot lethal is its capabilities to take control over users' phone. Apart from having Android banking trojan functionalities, the malware exhibits overlay, keylogging, and ransomware functionalities.

The malware also contains commands for stealing emails and remotely starting apps. However, such tools are not active yet, meaning the malware is still in its development phase. MysteryBot is reportedly able to target the latest Android versions - Nougat and Oreo. Researchers say that the malware uses overlay screens designed to look like real bank site, but are run by attackers.

Advertisement

The researchers also said that a new technique abuses a service permission called 'Package Usage Stats' that is accessible through the Accessibility Service permission in Android phones. This method allows the trojan to enable and abuse any other permission without the user's consent.

Advertisement

The MysteryBot also contains a keylogger. But researchers said that none of the already-known keylogging techniques was used. Instead, the malware calculates the location for each row and places a view over each key.

"This view has a width and height of zero pixels and due to the "FLAG_SECURE" setting used, the views are not visible in screenshots. Each view is then paired to a specific key in such a way that it can register the keys that have been pressed which are then saved for further use," said researchers. However, they added, "The code for this the keylogger seems to still be under development as there is no method yet to send the logs to the C2 server."

Advertisement

The malware also has inbuilt ransomware to individually encrypt all files in the external storage directory, including every subdirectory, after which the original files are deleted. "The encryption process puts each file in an individual ZIP archive that is password protected, the password is the same for all ZIP archives and is generated during runtime. When the encryption process is completed, the user is greeted with a dialog accusing the victim of having watched pornographic material," said researchers.

From the looks of it, MysteryBot is not quite widespread as it is still under development. However, you should be aware of any apps that ask for an excessive number of permissions, and always install apps from trusted sources, such as Google Play.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: MysteryBot, Malware
Advertisement
Popular Mobile Brands
  1. Saiyaara is All Set to Stream on This OTT Platform in September
  2. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  3. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  4. Vivo Launches Y500 in China With a Massive 8,200mAh Battery
  5. Motorola Razr 60, Buds Loop With Swarovski Crystals Debut in India
  6. Apple Marks iPhone 8 Plus as Vintage Alongside These MacBook Models
  7. Realme 15T 5G India Launch Today: All You Need to Know
  8. Realme Watch 5 Design, Key Features Leaked Ahead of Debut
  1. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  2. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  3. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  4. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  5. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  6. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  7. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
  8. YouTube Reportedly Cracks Down on Premium Family Plan Sharing With Location-Based Checks
  9. Redmi 15 5G, Redmi 14 Pro 5G Series Prices Dropped During Diwali With Xiaomi Sale
  10. Amazon Great Indian Festival Sale 2025: Deals and Discounts on Samsung Phones, Laptops, and More Teased
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.