{"id":1894,"date":"2025-02-11T10:03:37","date_gmt":"2025-02-11T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/11\/finstealer-malware-attacking-leading-indian-banks-mobile-users-to-steal-login-credentials\/"},"modified":"2025-02-11T10:03:37","modified_gmt":"2025-02-11T10:03:37","slug":"finstealer-malware-attacking-leading-indian-banks-mobile-users-to-steal-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/11\/finstealer-malware-attacking-leading-indian-banks-mobile-users-to-steal-login-credentials\/","title":{"rendered":"FinStealer Malware Attacking Leading Indian Bank\u2019s Mobile Users To Steal Login Credentials"},"content":{"rendered":"<p>    FinStealer Malware Attacking Leading Indian Bank\u2019s Mobile Users To Steal Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated malware campaign dubbed \u201cFinStealer\u201d is actively targeting customers of a leading Indian bank through fraudulent mobile applications.<\/p>\n<p>The malware, identified as Trojan.rewardsteal\/joxpk, employs advanced tactics to steal banking credentials and personal information from unsuspecting users.<\/p>\n<p>The malicious campaign operates through a suspicious website (motocharge[.]online) that distributes fake banking apps mimicking legitimate ones.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjBLCUWaedXTslQ4UEA3qY8egFtIElUdJMil3ZumbTaeXycP_r_kz_Eubyd_N9mSbzxylbtoWHV3PC1fVkUUVA2aDGnfTWVdmZwBXxsanQX48kjhgqgxuB8AbkKz-YdUgeGYukS2Ymd31-6MbK-q5i4uN_TI1w4aUQew5Suoem8-NB89VFn7ovK05xcW_8\/s16000\/APK%2520Details%2520%28Source%2520-%2520CYFIRMA%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">APK Details (Source \u2013 CYFIRMA)<\/figcaption><\/figure>\n<\/div>\n<p>CYFIRMA analysts identified that the malware is built using Kotlin and exhibits sophisticated capabilities.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgxZfW9XO85zA_uQkZ-hDajS8wwzqKM7OJI83wQKT-FXE9rt4mMLRAp-vV5gl7f-zmHPJR6kHcP5kBEvGOdntDusiB5OY9TNj5jcAiitkXR2_tlp85a-3ddz5pu76sYTwTGbO2g6D6WZchSTTPoYcntIz60h2mkOL92y1lUuLnczqhf6X3SENFxKHT_X0Q\/s16000\/Obfuscated%2520Code%2520%28Source%2520-%2520CYFIRMA%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Obfuscated Code (Source \u2013 CYFIRMA)<\/figcaption><\/figure>\n<\/div>\n<p>The capabilities include XOR-based string obfuscation to evade detection, a dual command-and-control (C2) infrastructure utilizing both IP-based servers (41.216.183.97) and Telegram bots, and advanced WebView exploitation for credential harvesting.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Core functionality of FinStealer<\/strong><\/h2>\n<p>Technical analysis revealed the malware\u2019s core functionality through this critical code snippet:-<\/p>\n<pre class=\"wp-block-code\"><code>public class NPStringFog {\n    public static String KEY = \"npmanager\";\n    private static final String hexString = \"0123456789ABCDEF\";\n    public static String decode(String str) {\n        ByteArrayOutputStream baos = new ByteArrayOutputStream(str.length() \/ 2);\n        for (int i = 0; i &lt; str.length(); i += 2) {\n            baos.write((hexString.indexOf(str.charAt(i)) &lt;&lt; 4) | hexString.indexOf(str.charAt(i + 1)));\n        }\n        \/\/... [obfuscation logic]\n    }\n}<\/code><\/pre>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhNLJ3MSlLi557cLlMNHS9VSfjoznkY9OxgJ7u1D7u1cVy00xW0oDt6fUhOcuz0ksSAwUQxoWjVrBznrwx7jYxGyalo16LfY6fAuFBJl6RIWAVjjHnF09qdTXOebT9tlZ0nRvGticQ_-t_9Y3yalafx0eKttUoSr3PktAnQhmmLEMHoM7EoYaSrVqKobug\/s16000\/Obfuscated%2520Module%2520%28Source%2520-%2520CYFIRMA%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Obfuscated Module (Source \u2013 CYFIRMA)<\/figcaption><\/figure>\n<\/div>\n<p>The malware communicates with its C2 infrastructure through a Telegram bot (API key: 7754264825:AAEqSBGNuEbuMqnWFqN7E_SvhS5sy_IFjEE) to exfiltrate sensitive data including:-<\/p>\n<ul class=\"wp-block-list\">\n<li>Banking credentials<\/li>\n<li>Credit card details<\/li>\n<li>Personal identification information<\/li>\n<\/ul>\n<p>Security researchers also discovered a critical vulnerability (CVE-2011-2688) in the C2 server, allowing SQL injection attacks through the mysql\/mysql-auth.pl script in the mod_authnz_external module.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjA5z6iStWvfQRoYbePeMaHVfTws496MlmXjIa9N-tb5smsEVfEo193tOnga9bynM4S7K30ntS2FQwG6Nw06UhuFRd3R5Q6EUkB_7IIXWajtSlvkx2P0mBnLAr7oEWLEcYMnEcgUiJeKSuqv6uwudwo2-nz7MTWWbfyei3TibQrDoElAxVTf-WefiKw40o\/s16000\/Snapshot%2520of%2520C2%2520Server%2520-%2520Admin%2520Panel%2520%28Source%2520-%2520CYFIRMA%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Snapshot of C2 Server \u2013 Admin Panel (Source \u2013 CYFIRMA)<\/figcaption><\/figure>\n<\/div>\n<p>To protect against this threat, CYFIRMA recommends implementing advanced endpoint protection, monitoring for exploit-like behavior, conducting regular security audits of mobile applications, and blocking known malicious indicators of compromise (IOCs).<\/p>\n<p>The following YARA rule can help detect the malware:-<\/p>\n<pre class=\"wp-block-code\"><code>rule Bank_Fraud_App {\n    meta:\n        author = \"CRT\"\n        description = \"Detects fraudulent mobile apps impersonating Bank\"\n    strings:\n        $telegram_bot = \"\/bot\" ascii nocase\n        $hex_pattern = { 6c 43 6c 43 6c 20 63 72 6564 6974 2063617264 }\n        $wix_webview = \"wixsite.com\" ascii nocase\n    condition:\n        any of ($telegram_bot, $hex_pattern, $wix_webview)\n}<\/code><\/pre>\n<p>Users are strongly advised to download banking applications only from official sources and verify app authenticity before installation.<\/p>\n<p>The campaign remains active, with researchers monitoring new variants and attack vectors as they emerge.<\/p>\n<h2 class=\"wp-block-heading\"><strong>IOCs<\/strong><\/h2>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhi1gF95bNQzU7BaWcPkw4DC_oapNb42ubwEboLmGSPomw9jh7zpG5RhKyuQNDMfJtKkQU90ApsbTueII0j6vbHZr_8sMEZuFRwB5t0V0Tjih55oYHk1CO1xmsRqlYRXtLYU09Kzqdn_l7M7PStIfRM53KNDzI37FFzc3Tbu1RPqJnZSNtXDXXsWcyPY7k\/s16000\/IOCs%2520%28Source%2520-%2520CYFIRMA%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">IOCs (Source \u2013 CYFIRMA)<\/figcaption><\/figure>\n<\/div>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Are you from SOC\/DFIR Team? - Join 500,000+ Researchers to Analyze Cyber Threats with ANY.RUN Sandbox -\u00a0<a href=\"https:\/\/any.run\/demo\/?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=meme&amp;utm_content=demo&amp;utm_term=100225\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/finstealer-malware-attacking-leading-indian-banks-mobile-users\/\">FinStealer Malware Attacking Leading Indian Bank\u2019s Mobile Users To Steal Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/finstealer-malware-attacking-leading-indian-banks-mobile-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FinStealer Malware Attacking Leading Indian Bank\u2019s Mobile Users To Steal Login Credentials A sophisticated malware campaign dubbed \u201cFinStealer\u201d is actively targeting customers of a leading Indian bank through fraudulent mobile applications. The malware, identified as Trojan.rewardsteal\/joxpk, employs advanced tactics to steal banking credentials and personal information from unsuspecting users. The malicious campaign operates through a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,700,258],"tags":[130],"class_list":["post-1894","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-cyberattack-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1894"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1894"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1894\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}