XLoader Trojan Poses as Security App for Android

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,136
A new variant of the XLoader Trojan is targeting Android devices by posing as a security application, and also attempts to infect iPhones and iPads through a malicious iOS profile, Trend Micro reports.

Previously, the malware was observed posing as Facebook, Chrome, and other legitimate applications, in an attempt to trick users into downloading it. The new variant features an updated deployment technique and also contains changes in its code that set it apart.

The malware is hosted on fake websites that mimic legitimate domains, so as to trick users into downloading a fake security Android application package (APK). Links to the malicious websites are delivered to the intended victims via SMiShing, Trend Micro’s security researchers reveal.

On Android, the APK is installed only if the user has allowed the installation of apps from unknown sources. On iOS devices, users are served a phishing page, but only after they accept to install a malicious configuration profile that claims to resolve an issue preventing the site to load.

The malware leverages Twitter profiles to encode its real command and control (C&C) addresses in the Twitter names. It also includes a comment to collect unique identifiers of mobile devices such as IMSI, ICCID, Android ID, and device serial number.

“Considering the other malicious behaviors of XLoader, this added operation could be very dangerous as threat actors can use it to perform targeted attacks,” Trend Micro notes.

On Apple devices, the malicious iOS profile gathers the unique device identifier (UDID), International Mobile Equipment Identity (IMEI), Integrated Circuit Card ID (ICCID), mobile equipment identifier (MEID), version number, and product number.

“After the profile is installed, the user will then be redirected to another Apple phishing site. The phishing site uses the gathered information as its GET parameter, allowing the attacker to access the stolen information,” the security researchers say.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top