‘BlackRock’ Android Malware Can Steal Banking Credentials, Says CERT-In

Android Malware

The country’s cyber security agency has issued an alert against an Android malware, dubbed “BlackRock”, that has the potential to “steal” banking and other confidential data of a user. It can extract credentials and credit card information from over 300 apps such as email, e-commerce apps, social media apps, besides banking and financial apps, the CERT-In said in an advisory.

The “attack campaign” of this ‘Trojan’ category malware is active globally, said the Computer Emergency Response Team of India (CERT-In), the national technology arm to combat cyber-attacks and guard Indian cyberspace. The BlackRock Android malware was initially reported by ThreatFabric earlier this month, and first spotted in May.

It is reported that a new Android malware strain dubbed ‘BlackRock’ equipped with data-stealing capabilities is attacking a wide range of Android applications. The malware is developed using the source code of Xerxes banking malware which itself is a variant of LokiBot Android Trojan. 

Also Read: Apple Suppliers, Samsung Apply for PLI Scheme by Government

The “noteworthy feature” of this malware is that its target list contains 337 applications including banking and financial applications, and also non-financial and well-known commonly used brand name apps on an Android device that focus on social, communication, networking and dating platforms. It can steal credentials and credit card information from over 300 plus apps like email clients, e-commerce apps, virtual currency, messaging or social media apps, entertainment apps, banking and financial apps.

Threat operators can issue a number of commands for various operations such as logging keystrokes, spamming the victims” contact lists with text messages, setting the malware as the default SMS manager, pushing system notifications to the C2 (command and control) server, locking the victim in the device home screen and steal and hide notifications, send spam and steal SMS messages and many more such activities, the advisory said.

The federal cyber security agency suggested some counter-measures: do not download and install applications from untrusted sources and use reputed application market only; always review the app details, number of downloads, user reviews and check “additional information” section before downloading an app from play store, use device encryption or encrypt external SD card; avoid using unsecured, unknown Wi-Fi networks among others.

Also, when it comes to downloading banking apps one should use the official and verified version and users should make sure they have a strong AI-powered mobile anti-virus installed to detect and block this kind of tricky malware.