Close Menu

    Ecosistema Stacks Defi: las mejores aplicaciones y herramientas STX DeFi (con comentarios)

    May 5, 2024

    Minería a través del halving de Bitcoin: estrategias de supervivencia para 2024

    April 14, 2024

    Los 7 principales fabricantes de baterías de iones de litio

    April 14, 2024

    El retroceso del mercado alcista de las criptomonedas | Sin banco

    April 14, 2024
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    despertarcripto.com
    • Home
    • Blog
    • Criptomonedas
    • Blockchain
    • DeFi
    • Privacidad Cripto
    • NFT & Arte Digital
    • Airdrop
    • Educacional
    • Regulación
    • Seguridad
    despertarcripto.com
    Home»Seguridad»Latest Android Banking Trojan Leveraging Simple RealTime Server (SRS) for C&C Communication — Cyble
    Seguridad

    Latest Android Banking Trojan Leveraging Simple RealTime Server (SRS) for C&C Communication — Cyble

    despertarcripto.comBy despertarcripto.comFebruary 5, 2024No Comments10 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Key Takeaways 

    • A novel Android Banking Trojan, “Greenbean”, is being disseminated through a phishing site promoting a cryptocurrency scheme. 
    • The malware is designed to target five applications across cryptocurrency, payment, and banking platforms. 
    • Evidence from the application’s name and the presence of Chinese and Vietnamese characters in the target code indicates that the malware is specifically aimed at Android users in China and Vietnam. 
    • The malware predominantly relies on the Accessibility service to gather credentials from the targeted applications. 
    • An additional feature of the Greenbean malware is its incorporation of video streaming using WebRTC. 
    • At the time of publishing the blog, the phishing site was operational, suggesting that the malware remains active in the wild. 
    • The malware utilizes the open-source Simple Realtime Server (SRS) project for its Command and Control (C&C) server, which supports WebRTC streaming. 

    Overview 

    In October 2023, Cyble Research and Intelligence Labs (CRIL) identified a new Android Banking Trojan named Enchant that specifically targets cryptocurrency users in China. More recently, another Android Banking Trojan featuring a video streaming and screen reading capability has been detected, focusing on targeting cryptocurrency users in China and Vietnam since August 2023. 

    CRIL has observed that this Banking Trojan is being disseminated through a phishing site, “hxxp://antlercryptop[.]com/,” which promotes a cryptocurrency scheme. Additionally, the malware is distributed via an Amazon AWS hosting service URL, namely “hxxps://hkccg[.]s3.ap-southeast-1.amazonaws.com/app-relea.apk.” 

    Figure 1 – Phishing site distributing malware