Bitcoin Forum
May 06, 2024, 01:13:17 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Warning]: Sova - new Android banking + crypto wallets trojan  (Read 102 times)
cryptomaniac_xxx (OP)
Hero Member
*****
Offline Offline

Activity: 1498
Merit: 566



View Profile
September 13, 2021, 01:27:42 AM
Merited by The Cryptovator (10), DdmrDdmr (6), Baofeng (1), bL4nkcode (1), vv181 (1)
 #1

Another new trojan was discovered recently, dubbed as SOVA - which is a Russian word for "Owl". It stand out from other Android malware/trojan is that it is a session cookie theft. What makes it dangerous is that the criminals can now have access to valid logged in sessions without needing your banking credentials.

Quote
Functionalities of the bot, as advertised by its authors, include:
Steal Device Data.
Send SMS.
Overlay and Cookie injection.
Overlay and Cookie injection via Push notification.
USSD execution.
Credit Card overlays with validity check.
Hidden interception for SMS.
Hidden interception for Notifications.
Keylogger.
Uninstallation of the app.
Resilience from uninstallation from victims.

screenshot of VirusTotal:



Quote
Clipper & Cryptocurreny wallets

Another feature that is incorporated in S.O.V.A., that we observed in other malware like Medusa, is the ability of altering the data in the system clipboard. The bot sets up an event listener, designed to notify the malware whenever some new data is saved in the clipboard. If the string of data is potentially a cryptocurrency wallet address, S.O.V.A. substitutes it with a valid address for the corresponding cryptocurrency.

Quote
The supported cryptocurrencies are Bitcoin, Ethereum, Binance coin, and TRON. The relative addresses can be found in the IOC section.

The good thing though is that no one has fallen victims so far, but who knows, maybe when it goes and scattered in the wild victims are going to come out.



You can read it here: https://www.threatfabric.com/blogs/sova-new-trojan-with-fowl-intentions.html

.
 airbet 
██
██
██
██
██
██
██
██
██
██
██
██
██
 .

▄████▄▄▄██████▄
███████████████
███████████████
███████▀▀▀▀████
██████████████
▀███▀███████▄██
██████████▄███
██████████████
███████████████
███████████████
██████████████
█████▐████████
██████▀███████▀
▄███████████████▄
████████████████
█░██████████████
████████████████
████████████████
█████████████████
█████████████████
███████░█░███████
████████████████
█████████████████
██████████████░█
████████████████
▀███████████████▀
.
.
.
.
██▄▄▄
████████▄▄
██████▀▀████▄
██████▄░░████▄
██████████████
████████░░▀███▌
░████████▄▄████
██████████████▌
███░░░█████████
█████████░░░██▀
░░░███████████▀
██████░░░██▀
░░▀▀███▀

   
|.
....
██
██
██
██
██
██
██
██
██
██
██
██
██
.
 PLAY NOW 
1714957997
Hero Member
*
Offline Offline

Posts: 1714957997

View Profile Personal Message (Offline)

Ignore
1714957997
Reply with quote  #2

1714957997
Report to moderator
1714957997
Hero Member
*
Offline Offline

Posts: 1714957997

View Profile Personal Message (Offline)

Ignore
1714957997
Reply with quote  #2

1714957997
Report to moderator
1714957997
Hero Member
*
Offline Offline

Posts: 1714957997

View Profile Personal Message (Offline)

Ignore
1714957997
Reply with quote  #2

1714957997
Report to moderator
Each block is stacked on top of the previous one. Adding another block to the top makes all lower blocks more difficult to remove: there is more "weight" above each block. A transaction in a block 6 blocks deep (6 confirmations) will be very difficult to remove.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714957997
Hero Member
*
Offline Offline

Posts: 1714957997

View Profile Personal Message (Offline)

Ignore
1714957997
Reply with quote  #2

1714957997
Report to moderator
1714957997
Hero Member
*
Offline Offline

Posts: 1714957997

View Profile Personal Message (Offline)

Ignore
1714957997
Reply with quote  #2

1714957997
Report to moderator
1714957997
Hero Member
*
Offline Offline

Posts: 1714957997

View Profile Personal Message (Offline)

Ignore
1714957997
Reply with quote  #2

1714957997
Report to moderator
DdmrDdmr
Legendary
*
Offline Offline

Activity: 2310
Merit: 10758


There are lies, damned lies and statistics. MTwain


View Profile WWW
September 13, 2021, 07:57:27 AM
Merited by cryptomaniac_xxx (1)
 #2

The BTC address shown in the article has TXs dating back from March 2021, being the most recent from July 2021, so with a bit of luck it’s not too active/lucky on the crypto front (maybe so on the banking area).
 
The address has TXs from months before the SOVA was detected, which can be read in many ways (it could have gone undetected for months, it could be an address used on prior similar software, and so forth).

According to the article, amongst other features, SOVA substitutes crypto addresses for their own through clipboard hijacking. It probably has the capability to steal crypto site’s passwords (there are some mentions to Coinbase, Local Bitcoins and Delta portfolio tracker).
Yaunfitda
Hero Member
*****
Offline Offline

Activity: 2842
Merit: 575



View Profile
September 14, 2021, 12:48:20 PM
Merited by cryptomaniac_xxx (1)
 #3

^ Yah, as this is a mutating malware, it could possibly read any crypto related activities, passwords, accounts to exchanges or wallets and then steal our passwords.

And maybe they have improved other malware capabilities like Medusa that's why this is really very dangerous if you get infected by this android malware.

███████████████████████████████
███████████████████████████████
███▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀███████████
█████████████▀▀        ▀▀██████
██████▀▀▀▀▀▀              ▀████
██████████▀     ▄▄██▄▄     ▀███
██████████      ██████      ███
██████████▄     ▀▀██▀▀     ▄███
██████▄▄▄▄▄▄              ▄████
█████████████▄▄        ▄▄██████
███▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████████
███████████████████████████████
███████████████████████████████
.
|
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
SSC NAPOLI
OFFICIAL EUROPEAN
BETTING PARTNER
|.ROLLBOTS.|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
▄█████████▀████████▀████▄
██████▄▄▄█████▄▄█████████
█████████████████████████
██████▀▀▀█████▀▀█████████
▀█████████▄████████▄████▀
▀██▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
ROLLBIT COIN
TRADE RLB NOW!
|...PLAY NOW...
bL4nkcode
Copper Member
Legendary
*
Offline Offline

Activity: 2142
Merit: 1305


Limited in number. Limitless in potential.


View Profile
September 14, 2021, 06:10:33 PM
Merited by cryptomaniac_xxx (1)
 #4

Interesting development of this trojan, didn't expect it could be explained as detailed such this. While it's a threat/malware, such bot will probably a good help in detecting various user's action in a different way, only if will be used for good, but that's not the case here.

I wonder if the latest android patch have this malware recorded already so it will be easily detected and will avoided too.
Baofeng
Legendary
*
Offline Offline

Activity: 2590
Merit: 1658



View Profile
September 14, 2021, 09:36:52 PM
Merited by cryptomaniac_xxx (1)
 #5

I wonder if the latest android patch have this malware recorded already so it will be easily detected and will avoided too.

I'm not really sure though, most of the time, they are late on releasing the patch, the malware authors could have make money already before they can take actions. And the the cat and mouse game continue, they patch it, threat actors released a new version of the malware and trojan. Maybe in the next version, we might see more crypto being targeted as well and then improved it a bit to not get detected easily by malware hunters.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!