Security News > 2024 > March > Vultur banking malware for Android poses as McAfee Security app
Security researchers found a new version of the Vultur banking trojan for Android that includes more advanced remote control capabilities and an improved evasion mechanism.
A report from Fox-IT, part of the NCC Group, warns that a new, more evasive version of Vultur spreads to victims through a hybrid attack that relies on smishing and phone calls that trick the targets into installing a version of the malware that masquerades as the McAfee Security app.
The call is answered by a fraudster who persuades the victim to open the link arriving with a second SMS, which directs to a site that offers a modified version of the McAfee Security app.
Inside the trojanized McAfee Security app is the 'Brunhilda' malware dropper.
The latest version of Vultur malware that researchers analyzed keeps several key features from older iterations, such as screen recording, keylogging, and remote access via AlphaVNC and ngrok, allowing attackers real-time monitoring and control.
PixPirate Android malware uses new tactic to hide on phones.
News URL
Related news
- PixPirate Android Banking Trojan Using New Evasion Tactic to Target Brazilian Users (source)
- PixPirate Android malware uses new tactic to hide on phones (source)
- Drozer: Open-source Android security assessment framework (source)
- Vultur Android Banking Trojan Returns with Upgraded Remote Control Capabilities (source)
- Winnti's new UNAPIMON tool hides malware from security software (source)
- SoumniBot malware exploits Android bugs to evade detection (source)
- New Brokewell malware takes over Android devices, steals data (source)
- New 'Brokewell' Android Malware Spread Through Fake Browser Updates (source)
- New Wpeeper Android malware hides behind hacked WordPress sites (source)
- ZLoader Malware Evolves with Anti-Analysis Trick from Zeus Banking Trojan (source)