Categories: Technology

Android malware BRATA removes data from phone after stealing it



The most popular mobile platform in the world is not safe heaven, with more users than any other. With large user base cybercriminals target the platform to get the most out of it, and we’ve seen the platform targeted time and time again over the years with varying degrees of success. One malware that has proved to be particularly difficult to shake off has been BRATA, a remote access trojan that has been used to steal banking details in the past. Now an updated version of the malware has been discovered in the wild, and it has a few new capabilities — including the ability to wipe your phone’s data as a kill-switch.

A report from computer security firm Cleafy (via Bleeping Computer) outlines how this new BRATA variant operates. In short, it has now been updated to attempt to evade antivirus scanners, keylog, and factory reset the smartphone. There are different variants of BRATA aimed at different audiences, targeting e-banking users in the UK, Poland, Italy, Spain, China, and Latin America.BRATA.A  added the GPS tracking feature and factory reset ability, and BRATA.B has the same features plus more obfuscated code and tailored overlay pages for specific banks to capture login details.

The solution used to deploy the malware on smartphones through BRATA.C is to use a primary app that can then download and install a secondary app with the malware. The best way to avoid being infected is to be careful about which apps you provide accessibility or admin access to. BRATA makes use of accessibility service permissions to view what’s on your screen, including screenshots and user keystrokes.

The biggest change though is the introduction of a remote factory reset, which appears to be executed once a user’s banking details have been successfully stolen. It is also executed when BRATA suspects it is being run in a virtual environment. This can only be done if you give the app administrator access to your phone. There are many pieces of malware circulating online that could potentially infect your smartphone, and the best way to avoid becoming a victim is to ensure vigilance in what apps you install. Typically, the best way to avoid getting caught out is to never give accessibility permissions or administrator permissions to any app and to only install apps from recognized distribution platforms.



Source

Recent Posts

What Is a Virtual Data Room? A Beginner’s Guide for First-Time Users

If you've never used one before, the term data room can sound more intimidating than…

3 days ago

Apple Vision Pro: Company cuts hundreds of jobs in the VR and Siri team

High price, too much weight and a narrow niche: the Vision Pro headset forces Apple…

3 days ago

US power grids: Trump declares a state of emergency

US President Donald Trump has ordered a new emergency regulation for the power grid. It…

3 days ago

Huawei Opens Sales of Watch GT 7 Pro ahead of global launch

Huawei has officially launched the sale of the Watch GT 7 Pro in China, introducing…

3 days ago

Apple to transform the next generation of smart glasses into a health and fitness product

Apple is considering the potential to transform its future smart glasses into health and fitness…

3 days ago

6 Practical Ways to Stop Letting Your Past Define Who You Are

Everyone has parts of their past they'd handle differently if given another chance. Maybe you…

3 days ago