Security News > 2024 > April > SoumniBot malware exploits Android bugs to evade detection

SoumniBot malware exploits Android bugs to evade detection
2024-04-17 21:38

A new Android banking malware named 'SoumniBot' is using a less common obfuscation approach by exploiting weaknesses in the Android manifest extraction and parsing procedure.

The method enables SoumniBot to evade standard security measures found in Android phones and perform info-stealing operations.

The malware was discovered and analyzed by Kaspersky researchers, who provide the technical details on the methods the malware uses to take advantage of the Android routine to parse and extract APK manifests.

First, SoumniBot uses an invalid compression value when unpacking the APK's manifest file, which diverges from the standard values expected by the Android 'libziparchive' library tasked with the role.

Anatsa Android malware downloaded 150,000 times via Google Play.

Vultur banking malware for Android poses as McAfee Security app.


News URL

https://www.bleepingcomputer.com/news/security/soumnibot-malware-exploits-android-bugs-to-evade-detection/