What is TrickMo Malware?
TrickMo is a powerful Android banking trojan that was first observed in September 2019 by CERT-Bund. It is thought to be the work of the now-defunct TrickBot e-crime gang, and based on the original source code, its new iterations have been released from time to time with enhanced anti-analysis and anti-detection techniques. Based on the latest analysis of its improperly secured command and control infrastructure (C2), which yielded about 13,000 unique IP addresses, it has been found to target users in Canada, followed by the United Arab Emirates, Turkey, and Germany.
Nature and Capabilities of TrickMo Malware
TrickMo malware uses the Android accessibility services to give itself additional permissions and tap on prompts as needed. The malware is capable of granting remote control over infected devices. As a banking trojan, in order to steal account credentials from various banks, it serves users overlays of phishing login screens for those banks. It is also capable of stealing SMS-based OTPs, screen recording, and data exfiltration. As the malware can dismiss keyguards and auto-accept permissions, these capabilities enable it to integrate seamlessly into the device's operations. Because the malware has access to Android accessibility services, it can disable crucial security features and system updates, auto-grant permissions at will, and prevent the uninstallation of certain apps. According to analysts, the deceptive user interface is an HTML page hosted on an external website, and it is displayed in full-screen mode on the device, making it look like a legitimate screen. When the user enters their unlock pattern or PIN, the fake lock screen transmits the captured PIN or pattern to the command and control server along with a unique device identifier. Because the malware steals the device unlock PIN, it can unlock the phone in the late hours when it is not being monitored to perform on-device fraud.
Infection and Threat from TrickMo Malware
The TrickMo trojan is installed through a dropper app that masquerades as Google Chrome, and when launched after installation, it urges the victim to update Google Play Services by clicking the Confirm button. As the user proceeds with the update, an APK file containing the TrickMo payload is downloaded to the device under the guise of “Google Services,” after which the user is asked to enable accessibility services for the new app.
According to Google, it has not found any evidence of malware being distributed and infecting users via the Google Play Store. New updated variants of TrickMo malware have been discovered from time to time with enhanced anti-analysis features to evade detection. Most recently, forty new variants of the TrickMo trojan have been identified in the wild, linked to 16 droppers and 22 distinct command and control (C2) infrastructures, with new features designed to steal Android PINs.
Another great threat to users from TrickMo malware is its poorly configured and unsecured command and control servers, which significantly elevate the risk of theft of sensitive user information by other malicious actors. This is a security lapse on the part of the threat actors, and it puts the sensitive data of the victims at risk from other threat actors. The sensitive data exfiltrated from the devices includes credentials and pictures, without requiring any authentication. This information can further be leveraged to commit identity theft, infiltrate various online accounts, make fraudulent purchases, and carry out unauthorized fund transfers. The leaked or stolen user data also opens the door to sophisticated social engineering attacks and long-term, difficult-to-recover damage to the financial assets and reputation of users.
How to Safeguard Yourself
To safeguard themselves, users need to follow the usual security practices, like downloading apps from trustworthy developers on the official Google Play Store, and being wary of giving apps sensitive permissions such as the accessibility services permission.
Users also need to monitor their credit history and transactions to spot any unauthorized transactions, and report any fraud to the bank at the earliest.
To help you stay aware, use a security app like our app Malloc. Malloc flags any app that has been granted the accessibility service, so a risky permission does not go unnoticed, and it helps you see where apps are sending data so you can spot suspicious behaviour. Detection on Malloc runs on the device, and the broader picture is covered in our mobile security section. Malloc detects and reduces risk; it cannot guarantee that no threat ever succeeds.
References: BleepingComputer — TrickMo malware steals Android PINs using fake lock screen; The Hacker News — TrickMo Banking Trojan Can Now Capture Android PINs and Unlock Patterns; The Hacker News — TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud.
Relevant tags:
Published on Medium