Android Malware Families Target 800+ Banking, Crypto Apps With Near-Zero Detection Rates: Zimperium

Gate News message, April 25 — Cybersecurity firm Zimperium has identified four active malware families—RecruitRat, SaferRat, Astrinox and Massiv—targeting over 800 applications across banking, cryptocurrency and social media sectors. The campaigns employ advanced anti-analysis techniques and structural APK tampering to maintain near-zero detection rates against traditional signature-based security mechanisms.

Attackers use phishing websites, fraudulent job offers, fake software updates, text-message scams and promotional lures to trick users into installing malicious Android apps. Once installed, the malware requests Accessibility permissions to hide app icons, block uninstall attempts, steal PINs and passwords via fake lock screens, intercept one-time passcodes, record live device screens and overlay counterfeit login pages on legitimate banking or crypto applications.

Overlay attacks form the core of the credential-harvesting strategy. The malware monitors the foreground using Accessibility Services and detects when a victim launches a financial app, then fetches a malicious HTML payload and overlays it onto the legitimate interface to create a convincing deceptive facade.

The campaigns use HTTPS and WebSocket communications to blend malicious traffic with normal app activity, with some variants employing additional encryption layers to further evade detection.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments