Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » A new Octo2 Android banking trojan has appeared with device hijacking capabilities
Global Security

A new Octo2 Android banking trojan has appeared with device hijacking capabilities

AdminBy AdminSeptember 24, 2024No Comments3 Mins Read
Octo2 Android Banking Trojan
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


September 24, 2024Ravi LakshmananMobile Security / Cybercrime

Android banking trojan Octo2

Cybersecurity researchers have discovered a new version of the Android banking trojan called Octo that comes with enhanced device hijacking capabilities (DTO) and perform fraudulent transactions.

The new version received a code name October 2 Dutch security firm ThreatFabric said in a report shared by The Hacker News, adding that the malware distribution campaigns were spotted in European countries such as Italy, Poland, Moldova and Hungary.

“Malware developers have taken steps to improve the stability of the remote capabilities required for Device Takeover attacks,” the company said in a statement. said.

Cyber ​​security

Some of the malware that Octo2 contains are listed below –

  • Europe Enterprise (com.xsusb_restore3)
  • Google Chrome (com.havirtual06numberresources)
  • NordVPN (com.handedfastee5)

Okto was the first is indicated campaign in early 2022, describing it as the work of a threat actor using the online aliases Architect and goodluck. It was judged to be a “direct descendant” of the Exobot malware originally discovered in 2016, which also spawned another variant called Coper in 2021.

“Based on the source code of the Marcher banking trojan, Exobot was maintained until 2018, targeting financial institutions with various companies targeting Turkey, France, and Germany, as well as Australia, Thailand, and Japan,” ThreatFabric noted at the time.

“A ‘lite’ version was then introduced, named by the author of ExobotCompact, a threat creator known as ‘android’ on dark web forums.”

The emergence of Octo2 is said to have been primarily triggered by the leak of Octo’s source code earlier this year, which led to other threat actors spawning several variants of the malware.

Another important development is Octo’s transition to a malware-as-a-service (MaaS) operation, according to Team Cymru, which allows the developer to monetize the malware by offering it to cybercriminals looking to carry out information-stealing operations.

“While promoting the update, Octo owner announced that Octo2 will be available to Octo1 users at the same early access price,” ThreatFabric said. “We can expect the entities that operated Octo1 to move to Octo2, thus bringing it into the global threat landscape.”

One of the significant improvements in Octo2 is the introduction of the Domain Generation Algorithm (DGA) to generate the command and control (C2) server name, as well as improvements to its overall stability and anti-analysis techniques.

Cyber ​​security

Fake Android apps that distribute malware are created using a well-known APK tethering service called Zombinderwhich allows legitimate applications to be trojanized so that they extract real malware (in this case Octo2) under the guise of installing a “required plugin”.

“Because the source code of the Octo malware was already leaked and readily available to various threat actors, Octo2 builds on this foundation with even more robust remote access capabilities and sophisticated obfuscation techniques,” ThreatFabric said.

“This option’s ability to stealthily perform device fraud and intercept sensitive data, combined with the ease with which it can be configured by various threat actors, raises the stakes for mobile banking users worldwide.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.