Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

New BlankBot Android Trojan Can Steal User Data

The BlankBot Android trojan exfiltrates user data, executes C&C commands, and supports custom injections, keylogging, and screen recording.

A new Android trojan provides attackers with a broad range of malicious capabilities, including command execution, Intel 471 reports.

Dubbed BlankBot, the trojan was initially observed on July 24, but Intel 471 has identified samples dated at the end of June, almost all of which remain undetected by most antivirus software.

The threat is posing as utility applications and appears to be targeting Turkish Android users now, but could soon be used in attacks against users in more countries.

Once the malicious application has been installed, the user is prompted to grant accessibility permissions on the premises that they are required for correct execution. Next, on the pretense of installing an update, the malware enables all the permissions it requires to gain control of the device.

On Android 13 or newer devices, a session-based package installer is used to bypass restrictions and the victim is prompted to enable installation from third-party sources.

Armed with the necessary permissions, the malware can log everything on the device, including sensitive information, SMS messages, and applications lists, and can perform custom injections to steal bank information and lock patterns.

Advertisement. Scroll to continue reading.

BlankBot establishes communication with its command-and-control (C&C) server by sending device information in an HTTP GET request, but switches to the WebSocket protocol for subsequent communication.

The threat uses Android’s MediaProjection and MediaRecorder APIs to record the screen and abuses accessibility services to retrieve data from the device, but implements a custom virtual keyboard to intercept key presses and send them to the C&C.

Based on a specific command received from the C&C, the trojan creates a customized overlay to ask the victim for banking credentials and personal and other sensitive information.

Additionally, the threat uses the WebSocket connection to exfiltrate victim data and receive commands from the C&C, which allow the attackers to launch or stop various BlankBot functionality, such as screen recording, gestures, overlay creation, data collection, and application deletion or execution.

“BlankBot is a new Android banking trojan still under development, as evidenced by the multiple code variants observed in different applications. Regardless, the malware can perform malicious actions once it infects an Android device, which include conducting custom injection attacks, ODF or stealing sensitive data such as credentials, contacts, notifications, and SMS messages,” Intel 471 notes.

Related: BingoMod Android RAT Wipes Devices After Stealing Money

Related: Sensitive Information Stolen in LetMeSpy Stalkerware Hack

Related: Millions of Smartphones Distributed Worldwide With Preinstalled ‘Guerrilla’ Malware

Related: Google Introduces Private Compute Services for Android

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

David Cass has joined Grayscale Investments as Chief Risk Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.