Octo2 Malware Strikes Mobile Banking Users

Oct 8, 2024 | Android
Author image

Liza Charalambous

Co-Founder & CTO at Malloc

Illustration of mobile banking under attack from the Octo2 Android banking trojan

Octo2 mobile banking trojan, which affects Android devices, is the second and latest iteration of the Octo malware first seen in 2022. The malware has stealth capabilities and is capable of device takeover to perform fraudulent transactions. It poses a significant challenge to the global mobile banking landscape, affecting both financial institutions and users of online mobile banking services.

Background of Octo2 Malware

Octo2 comes from the family of the Exobot banking trojan, which was first observed in 2016. Then there was ExobotCompact in 2019, a lighter version of Exobot that retained most of the features of the original Exobot malware. In 2021, a malware called ‘Coper’ was observed, which was found to be related to ExobotCompact. The first iteration of the Octo malware was seen from 2022 onwards, with the name Octo derived from ExobotCompact, and Octo was in fact built up from the ExobotCompact malware (2019). Octo malware was distributed and sold as malware-as-a-service by the authors of the malware. The source code of Octo malware was leaked in 2024 and multiple forks were created, and it effectively became free and widely available. To retain their business, the authors of the malware added significant improvements in the second iteration of Octo malware, called Octo2, and it is being offered at the same price as the original Octo malware.

Enhanced Capabilities of Octo2 Malware

The capabilities and enhancements of Octo2 malware include:

  • Increased stability of its remote action capabilities needed for device takeover attacks. For example, the remote operator of the malware can now enable a low-quality mode, suitable during poor network connectivity, decreasing the quality of screenshots sent to the malware operator.
  • Implementation of sophisticated obfuscation techniques to evade analysis and detection. The improved malicious code obfuscation implemented in Octo2, which comprises several steps including decryption and dynamically loading the malicious payload on the targeted device, makes it difficult to detect with both manual and automated malware analysis.
  • Implementation of a Domain Generation Algorithm (DGA) which generates domain names on the fly and renders DNS-based blocking ineffective, as the threat actors are able to quickly set up connections to new servers to evade blocks.

How does Octo2 Malware Infect Users?

Octo2 infects devices using infected versions of popular Android apps. These apps include Europe Enterprise, Google Chrome, and NordVPN. These modified versions of the popular apps are created using an APK binding service called Zombinder, which makes it possible to create trojanized versions of popular apps that download the actual malware payload by tricking users into installing an apparently necessary plugin, and this allows the malware to bypass Android OS 13+ restrictions.

According to Google, Octo2 malware is not known to spread via the Google Play Store and Google Play Protect safeguards users from the known versions of the malware. Therefore, Android users who sideload app APKs are at higher risk of getting their devices infected by the malware. Conversely, a social engineering attack might require users to sideload rogue versions of popular apps on their Android devices, thereby infecting them with the malware, and users should therefore be careful not to yield to such requests or circumstances.

Threat Landscape of Octo2 Malware

The Octo2 malware has been targeting European countries, and the samples were found in Italy, Poland, Hungary, and Moldova. It is expected that the threat actors will continue to target more people and countries, and therefore users should be on guard to protect the integrity and confidentiality of their finances and data.

Malloc is not a substitute for caution, but it adds a layer that catches what sideloaded apps do after install: it scans the device, alerts on malicious or dangerous apps, flags camera and microphone use in the background, and shows which domains apps contact. It detects and reduces risk rather than promising immunity. More on mobile security, and for developers, the Malloc security SDK.

References: Octo2: European Banks Already Under Attack by New Malware Variant (ThreatFabric); New Octo2 Android Banking Trojan Emerges with Device Takeover Capabilities (The Hacker News).

Relevant tags:

#Octo2#Android#Banking Trojan#Malware#Mobile Security#Malloc

Published on Medium

Related articles