Malware News New MysteryBot Android Malware Packs a Banking Trojan, Keylogger, and Ransomware

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Cybercriminals are currently developing a new strain of malware targeting Android devices which blends the features of a banking trojan, keylogger, and mobile ransomware.
Named MysteryBot, this malware strain is still under development, according to security researchers from ThreatFabric, who recently ran across this new threat.

MysteryBot has connections to LokiBot

ThreatFabric says MysteryBot appears to be related to the well-known and highly popular LokiBot Android banking trojan.

"Based on our analysis of the code of both Trojans, we believe that there is indeed a link between the creator(s) of LokiBot and MysteryBot," a ThreatFabric spokesperson told Bleeping Computer via email today.

"This is justified by the fact that MysteryBot is clearly based on the LokiBot bot code," the spokesperson added.

Furthermore, according to a report the company published yesterday, the recent MysteryBot malware sends data to the same command and control (C&C) server used in a past LokiBot campaign, clearly suggesting they are being controlled and developed by the same person or group.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top