LokiBot Redux Attacks Massive List of Common Android Apps

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,176
Researchers have discovered a new variant of the LokiBot trojan called BlackRock, that’s attacking not just financial and banking apps, but also a massive list of well-known and commonly used brand-name apps on Android devices.

The apps targeted include: Amazon, eBay, Facebook, Grinder, Instagram, Netflix, PlayStation, Reddit, Skype, Snapchat, TikTok, Tinder, Tumblr, Twitter and VK, among many others, researchers said.

The malware, which ThreatFabric discovered in May, is derived from the source code of the Xerxes banking malware, which itself is a variant of LokiBot, researchers said in report posted online Thursday. The threat actor behind Xerxes made the source code to that malware public in 2019, a type of event that typically sets off a chain reaction of malware variants, researchers noted.

BlackRock is on one level a normal banking trojan, targeting banking and different crypto apps across various countries on at least five continents, including the United States, Japan, United Kingdom, Australia, France, Canada and Malaysia.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top