{"id":5885,"date":"2025-08-05T10:03:34","date_gmt":"2025-08-05T10:03:34","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/05\/new-android-malware-mimics-as-sbi-card-axis-bank-apps-to-steal-users-financial-data\/"},"modified":"2025-08-05T10:03:34","modified_gmt":"2025-08-05T10:03:34","slug":"new-android-malware-mimics-as-sbi-card-axis-bank-apps-to-steal-users-financial-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/05\/new-android-malware-mimics-as-sbi-card-axis-bank-apps-to-steal-users-financial-data\/","title":{"rendered":"New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data"},"content":{"rendered":"<p>    New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated new Android malware campaign has emerged targeting Indian banking customers through convincing impersonations of popular financial applications.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chinese-threat-actors-using-2800-malicious-domains-to-deliver-windows-specific-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious software<\/a> masquerades as legitimate apps from major Indian financial institutions, including SBI Card, Axis Bank, Indusind Bank, ICICI, and Kotak, deceiving users into downloading fake applications that steal sensitive financial information.<\/p>\n<p>The malware operates through carefully crafted phishing websites that closely replicate official banking portals, incorporating authentic visual elements and branding to establish credibility.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh-e1t-a6IpqR1n4wA33_4Q7i1knd67efTOk9tcz1CTSmUOnpiGMHFito_yjFt4ckTtxpjEu6rA0jMtKc70dKthO6l2AHL0DIPq86jUjuxziPlIt7IpeVJgcvW61MeGJdPKWMgoTSNgRNOkMoDEJe6Fagrq2oP3R7t5PtH32MZGfutEah6djdPvkgknQlg\/s16000\/Phishing%2520website%2520%28Source%2520-%2520McAfee%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Phishing website (Source \u2013 McAfee)<\/figcaption><\/figure>\n<\/div>\n<p>These fraudulent sites feature prominent \u201cGet App\u201d and \u201cDownload\u201d buttons that prompt unsuspecting users to install <a href=\"https:\/\/cybersecuritynews.com\/hackers-using-607-malicious-domains-to-deliver-apk-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious APK files<\/a> disguised as official banking applications.<\/p>\n<p>The campaign specifically targets Hindi-speaking users across India, leveraging cultural and linguistic familiarity to enhance its deceptive effectiveness.<\/p>\n<p>McAfee researchers <a href=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/android-malware-targets-indian-banking-users-to-steal-financial-info-and-mine-crypto\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this threat as particularly dangerous due to its dual-purpose architecture that combines traditional banking fraud with cryptocurrency mining capabilities.<\/p>\n<p>The malware not only harvests personal and financial data but also silently mines Monero cryptocurrency on infected devices, maximizing the attackers\u2019 financial gains from each compromised device.<\/p>\n<p>What distinguishes this campaign from conventional banking trojans is its sophisticated evasion mechanisms and remote activation capabilities.<\/p>\n<p>Upon installation, the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> presents users with a fake Google Play Store interface suggesting an app update is required.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhimE2XwOyn2IP4Ezvr3g7zYvhzEu28M7ZURWgbZpePBZsTAUnM5tm5EY2kgvf6qHm2DnAEFyy5Xqf9xPPfJ-f4-YC-FQ9O8H_902IYAW5iNtdd-N39xOZ7VSyHYg5GIoY6oyoCu_MWqh3lHu01FkolfsvjUSNO7x9uYUs8wBb2-lHFYHsyyXCILoyJc6I\/s16000\/Initial%2520screen%2520shown%2520by%2520the%2520dropper%2520app%2520%28Source%2520-%2520McAfee%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Initial screen shown by the dropper app (Source \u2013 McAfee)<\/figcaption><\/figure>\n<\/div>\n<p>This deceptive tactic builds user confidence while the malware prepares its malicious payload.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-advanced-payload-delivery-and-execution-mechanism\"><strong>Advanced Payload Delivery and Execution Mechanism<\/strong><\/h2>\n<p>The malware employs a sophisticated two-stage payload delivery system designed to evade static analysis and detection.<\/p>\n<p>Initially functioning as a dropper, the application stores an encrypted DEX file within its assets folder, which serves as the first-stage loader component.<\/p>\n<p>This encrypted payload is <a href=\"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> using XOR encryption, preventing immediate detection by security scanners.<\/p>\n<p>The first-stage loader decrypts and dynamically loads a second encrypted file containing the actual malicious payload.<\/p>\n<p>This layered approach ensures that no clearly malicious code appears in the main APK file, complicating forensic analysis and automated detection systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiIEbrVvcVoy2P1dxjh5wpXNM4sKFnvOQYeFJ3ts72BsyjRnsdu2URCe0fysRPY21UFaM2-lKLh3W7MVOl-Wmy9SAtjC34Pjbe3h1xvJ6UUCVn1OLJvzIYvMN67H6CPN0BAgp9JDGQ1RxyEVUTszSB62bGTTtnzjfzQuTKCAqL_9j3Kg1UutQYG4EWXy10\/s16000\/Fake%2520card%2520verification%2520screen%2520%28Source%2520-%2520McAfee%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake card verification screen (Source \u2013 McAfee)<\/figcaption><\/figure>\n<\/div>\n<p>Once the final payload executes, it presents victims with convincing fake banking interfaces that capture sensitive information including card numbers, CVV codes, and personal details.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/lemon-duck-cryptocurrency-mining-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency mining<\/a> functionality operates through Firebase Cloud Messaging, allowing attackers to remotely trigger mining operations using XMRig software.<\/p>\n<p>The malware downloads encrypted mining binaries from hardcoded URLs and executes them using ProcessBuilder, generating Monero cryptocurrency while remaining largely undetected on infected devices.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Integrate\u00a0<strong>ANY.RUN TI Lookup<\/strong>\u00a0with your SIEM or SOAR To Analyses Advanced Threats<\/strong>\u00a0-&gt;\u00a0<strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=atricle&amp;utm_campaign=want-to-detect-incidents-before&amp;utm_content=plans1&amp;utm_term=290725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try 50 Free Trial Searches<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-android-malware-mimics-as-sbi-card\/\">New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-android-malware-mimics-as-sbi-card\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data A sophisticated new Android malware campaign has emerged targeting Indian banking customers through convincing impersonations of popular financial applications. The malicious software masquerades as legitimate apps from major Indian financial institutions, including SBI Card, Axis Bank, Indusind Bank, ICICI, and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5885","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5885"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5885"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5885\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}