By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Security Parrot - Cyber Security News, Insights and ReviewsSecurity Parrot - Cyber Security News, Insights and Reviews
Notification
Latest News
OpenAI may use Associated Press archive for AI training
July 14, 2023
EU users can hold conversations with Google Bard from training set
July 14, 2023
Aptos, the new default font for Microsoft Office
July 14, 2023
BlackLotus UEFI bootkit sources published on GitHub
July 14, 2023
Hackers from the XDSpy cyber-espionage group attacked Russian organizations on behalf of the Ministry of Emergency Situations
July 14, 2023
Aa
  • News
  • Tutorials
  • Security InsiderComing Soon
  • Expert InsightComing Soon
Reading: 2FA defeated by an Alien?
Share
Security Parrot - Cyber Security News, Insights and ReviewsSecurity Parrot - Cyber Security News, Insights and Reviews
Aa
Search
  • News
  • Tutorials
  • Security InsiderComing Soon
  • Expert InsightComing Soon
Follow US
Security Parrot - Cyber Security News, Insights and Reviews > News > 2FA defeated by an Alien?
Alien
News

2FA defeated by an Alien?

Last updated: 2020/10/02 at 6:22 AM
Jim Koohyar Biniyaz Published September 27, 2020
Share
SHARE

Not an actual little green man mind you; but a newly discovered banking trojan called Alien.

Contents
Alien malware: capabilitiesA new trend?

This malware, which targets android devices, uses its advanced feature to bypass 2FA and steal users credentials with relative ease.

Once it has infected a device, Alien aims to steal passwords from over 200 mobile applications including big hitters in the banking app word (Bank of America and Capital One) and instant messaging apps like Telegram.

As tradition recently the malware appeared first on a underground forum advertised as a Malware as a service, and since then it has been used to target institutions worldwide, including Australia, France, Germany, Italy, Poland, Spain, Turkey, the U.K. and the United States.

Forum post
The fist signs of his origins. Credit image threatfabric

Having looked for its origins, researchers believe Alien is a “fork” of the infamous Cerberus banking malware, which has undergone a steady demise in use over the past year.

Alien malware: capabilities

The researchers at threatfabric pointed out that Alien malware is a rented banking Trojan which offers more than the average capabilities of “normal” Android banking Trojans.

It has common capabilities such as overlay attacks, control and steal SMS messages and harvest the contact list. It can leverage its keylogger for any use and therefore broaden the attack scope further than its target list. It also offers the possibility to install, start and remove applications from the infected device.

Most importantly, it offers a notifications sniffer, allowing it to get the content of all notifications on the infected device, and a RAT (Remote Access Trojan) feature (by abusing the TeamViewer application), meaning that the threat actors can perform the fraud from the victim’s device.

The complete list of features of Alien is as follows:

  • Overlaying: Dynamic (Local injects obtained from C2)
  • Keylogging
  • Remote access
  • SMS harvesting: SMS listing
  • SMS harvesting: SMS forwarding
  • Device info collection
  • Contact list collection
  • Application listing
  • Location collection
  • Overlaying: Targets list update
  • SMS: Sending
  • Calls: USSD request making
  • Calls: Call forwarding
  • Remote actions: App installing
  • Remote actions: App starting
  • Remote actions: App removal
  • Remote actions: Showing arbitrary web pages
  • Remote actions: Screen-locking
  • Notifications: Push notifications
  • C2 Resilience: Auxiliary C2 list
  • Self-protection: Hiding the App icon
  • Self-protection: Preventing removal
  • Self-protection: Emulation-detection
  • Architecture: Modular

A new trend?

2020 shows interesting changes to the mobile threat landscape, not only is there an increase in the number of new Android banking Trojans, many of them also bring innovative features.

More and more Trojans embed features that enable the criminals to take remote control of the infected device (RAT) – like the Alien Trojan itself – in order to perform the fraud from the victim’s device.

As the researchers pointed out there’s an interest from actors in recording and stealing more information surrounding the victim. How that information will be used or monetized can vary, it is just a matter of time before actors find out about the value of such information.

“In the case of Alien, advanced features such as the authenticator-code stealer and notifications-sniffer aside, the features of the Trojan are quite common”, they reported in the blog.

But one thing is for sure, we are looking at a new rising threat superstar!

Weekly Updates For Our Loyal Readers!

Jim Koohyar Biniyaz September 27, 2020
Share this Article
Facebook Twitter Email Copy Link Print

Archives

  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020

You Might Also Like

News

OpenAI may use Associated Press archive for AI training

July 14, 2023
News

EU users can hold conversations with Google Bard from training set

July 14, 2023
News

Aptos, the new default font for Microsoft Office

July 14, 2023
News

BlackLotus UEFI bootkit sources published on GitHub

July 14, 2023

© 2022 Parrot Media Network. All Rights Reserved.

  • Home
  • Parrot Media Group
  • Privacy Policy
  • Terms and Conditions
Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Go to mobile version
Welcome Back!

Sign in to your account

Lost your password?