Fake Google reCAPTCHA used to hide Android banking malware

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,176
The phishing campaign impersonates Google in attacks against banking institutions and their users.

Researchers have documented a recent phishing campaign targeting online banking users which masquerades as Google in its attempt to steal valuable credentials.

According to cybersecurity researchers from Sucuri, the attack wave against a Polish bank and its users is impersonating Google reCAPTCHA systems and panic-eliciting techniques to prompt victims to click on malicious links embedded in scam emails.

The emails in question contain a fake confirmation for a recent transaction, alongside a link to a malicious .PHP file.
Messages sent to would-be victims ask them to 'verify' these non-existent transactions by clicking on the link.

This attack method is nothing new, but the next stage is somewhat more unusual. If a victim fails to realize the message is fake and clicks on the link, they are not sent to a standard, fake replica of the bank, but rather the PHP file serves a fake 404 error page.

The page has a number of specifically defined user-agents which are limited to Google crawlers. If the request is not Google crawler-related -- in other words, alternative search engines are in use -- then the PHP script instead loads a fake Google reCAPTCHA made up of JavaScript and static HTML.

screenshot-2019-02-22-at-09-33-36.png


"This page does a decent job at replicating the look of Google's reCAPTCHA, but since it relies on static elements, the images will always be the same unless the malicious PHP file's coding is changed," the researchers say. "It also doesn't support audio replay, unlike the real version."

The browser agent is then re-checked to ascertain how the victim has visited the page. A .zip dropper is on offer, alongside a malicious .APK reserved for Android users who fill in the CAPTCHA and download the payload.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top