• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Saturday, September 20, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

New MaliBot Android banking malware spreads as a crypto miner

16 June 2022
in Mining
Reading Time: 3 mins read
A A
0
New MaliBot Android banking malware spreads as a crypto miner
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
Cryptohopper
ADVERTISEMENT

Cybersecurity researchers have discovered a new Android banking malware named MaliBot, which poses as a cryptocurrency mining app or the Chrome web browser to target users in Italy and Spain.

MaliBot focuses on stealing financial information such as e-banking service credentials, crypto wallet passwords, and personal details, while it’s also capable of snatching two-factor authentication codes from notifications.

According to a report by F5 Labs, whose analysts discovered the new malware, it’s currently using multiple distribution channels, likely aiming to cover the market gap created by the sudden shutdown of the FluBot operation.

Fake crypto-apps

Malibot’s command and control server is based in Russia, and its IP has been associated with several malware distribution campaigns dating as far back as June 2020.

The distribution of MaliBot takes place via websites that promote cryptocurrency applications in the form of APKs that victims download and install manually.

The sites that push these files are clones of real projects like TheCryptoApp, which has over a million downloads on the Google Play Store.

In another campaign, the malware is pushed as an app called Mining X, and the victims are tricked into scanning a QR code to download the malicious APK file.

The Mining X website that pushes MaliBot
The Mining X website that pushes MaliBot

MaliBot operators also use smishing (SMS phishing) messages to distribute their payloads to a list of phone numbers determined by the C2. These messages are sent from compromised devices abusing the “send SMS” permission.

MaliBot capabilities

MaliBot is a powerful Android trojan that secures accessibility and launcher permissions upon installation and then grants itself additional rights on the device.

It can intercept notifications, SMS, and calls, capture screenshots, register boot activities, and give its operators remote control capabilities via a VNC system.

VNC allows the operators to navigate between screens, scroll, take screenshots, copy and paste content, swipe, perform long presses, and more.

To bypass MFA protections, it abuses the Accessibility API to click on confirmation prompts on incoming alerts about suspicious login attempts, sends the OTP to the C2, and fills it out automatically.

Code to retrieve MFA codes
Code to retrieve MFA codes (F5 Labs)

Additionally, the malware can steal MFA codes from Google Authenticator and perform this action on-demand, opening the authentication app independently from the user.

Like most banking trojans, MaliBot retrieves a list of installed apps to determine which bank apps are used by the victim to fetch the matching overlays/injections from the C2. When the victim opens the legitimate app, the fake login screen is overlaid on top of the UI.

Sending list of overlays to C2 and receiving injections back
Sending list of overlays to C2 and receiving injections back (F5 Labs)

What we should expect

The F5 Labs analysts have seen unimplemented features in the code of MaliBot, like the detection of emulated environments that could be used to evade analysis.

This is a sign that the development is very active, and new versions of MaliBot are expected to enter circulation soon, possibly raising the potency of the novel malware.

For now, MaliBot loads overlays that target Italian and Spanish banks, but it could expand its scope soon by adding more injections, just like FluBot gradually did.

Spanish bank overlay used by MaliBot
Spanish bank overlay used by MaliBot (F5 Labs)

At the time of writing this, the websites distributing MaliBot remain online, so the malware distribution operation is still pretty much active.

Source link

[crypto-donation-box]
Tags: AndroidBankingcryptoMaliBotMalwareMinerSpreads
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

‘I Am Very Sorry’: Takashi Murakami Apologizes to His Crypto Investors on Twitter as His NFT Prices Nosedive

Next Post

‘Buy Bitcoin, plant a tree, lower your time preference’: A Sequoia story

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post

‘Buy Bitcoin, plant a tree, lower your time preference’: A Sequoia story

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
XRP Price Prediction, Latest Solana News And The Best Crypto To Buy Before Q4 – BlockchainReporter

XRP Price Prediction, Latest Solana News And The Best Crypto To Buy Before Q4 – BlockchainReporter

20 September 2025
BNB Rockets to New All-Time High of ,028 as Binance Stablecoin Reserves Smash  Billion – TradingView

BNB Rockets to New All-Time High of $1,028 as Binance Stablecoin Reserves Smash $40 Billion – TradingView

20 September 2025
LINK Price Eyes Major 125% Breakout Before Year Ends?

LINK Price Eyes Major 125% Breakout Before Year Ends?

20 September 2025
Solana Co-Founder Speaks on Quantum Computers, Warns Bitcoin Developers – Coinspeaker

Solana Co-Founder Speaks on Quantum Computers, Warns Bitcoin Developers – Coinspeaker

20 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • XRP Price Prediction, Latest Solana News And The Best Crypto To Buy Before Q4 – BlockchainReporter
  • BNB Rockets to New All-Time High of $1,028 as Binance Stablecoin Reserves Smash $40 Billion – TradingView
  • LINK Price Eyes Major 125% Breakout Before Year Ends?
  • Solana Co-Founder Speaks on Quantum Computers, Warns Bitcoin Developers – Coinspeaker
  • Can PUMP Token Price Recover After Smart Whales Lock In Profits?

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,779.00
  • ethereumEthereum (ETH) $ 4,480.86
  • xrpXRP (XRP) $ 2.98
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,022.98
  • solanaSolana (SOL) $ 238.70
  • usd-coinUSDC (USDC) $ 0.999617
  • dogecoinDogecoin (DOGE) $ 0.266482
  • staked-etherLido Staked Ether (STETH) $ 4,474.72
  • tronTRON (TRX) $ 0.347477
  • cardanoCardano (ADA) $ 0.891345
  • wrapped-stethWrapped stETH (WSTETH) $ 5,433.37
  • chainlinkChainlink (LINK) $ 23.28
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,830.32
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,673.00
  • hyperliquidHyperliquid (HYPE) $ 54.26
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • avalanche-2Avalanche (AVAX) $ 33.19
  • suiSui (SUI) $ 3.66
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.984526
  • stellarStellar (XLM) $ 0.385932
  • bitcoin-cashBitcoin Cash (BCH) $ 600.82
  • wrapped-eethWrapped eETH (WEETH) $ 4,818.11
  • wethWETH (WETH) $ 4,479.02
  • hedera-hashgraphHedera (HBAR) $ 0.242572
  • leo-tokenLEO Token (LEO) $ 9.49
  • litecoinLitecoin (LTC) $ 113.86
  • usdsUSDS (USDS) $ 1.00
  • crypto-com-chainCronos (CRO) $ 0.231076
  • the-open-networkToncoin (TON) $ 3.09
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,777.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • polkadotPolkadot (DOT) $ 4.37
  • whitebitWhiteBIT Coin (WBT) $ 43.39
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.222390
  • uniswapUniswap (UNI) $ 9.17
  • mantleMantle (MNT) $ 1.69
  • moneroMonero (XMR) $ 295.55
  • ethenaEthena (ENA) $ 0.667973
  • daiDai (DAI) $ 0.999985
  • aaveAave (AAVE) $ 296.79
  • pepePepe (PEPE) $ 0.000011
  • memecoreMemeCore (M) $ 2.55
  • okbOKB (OKB) $ 193.35
  • nearNEAR Protocol (NEAR) $ 3.16
  • bitget-tokenBitget Token (BGB) $ 5.30
  • jito-staked-solJito Staked SOL (JITOSOL) $ 293.81
  • story-2Story (IP) $ 10.89