• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

Researchers Warn About Phone-Wiping Banking Trojan

June 22, 2022

Researchers are warning that a well-known banking trojan is evolving into something even more insidious. The Brazilian Remote Access Tool, Android (BRATA) has been around in some form since 2019, and will intercept two-factor SMS codes and steal other device information that can be used to take over someone’s bank account.

Researchers Warn About Phone-Wiping Banking Trojan

BRATA is also famous for the extreme measures it takes to avoid detection. Once the fraudster has hacked into an account and completed a transaction, BRATA will wipe the victim’s phone using the Android factory reset setting. The reset prevents the victim from learning about and reporting the fraudulent transfer while there is still time to stop the exchange. The trojan (which only infects Android devices) will similarly trigger a factory reset if it is spotted by any security software that may be running on the victim’s phone.

The new version of BRATA is being distributed across more platforms, and is able to extract even more data before it decides to cover its tracks. With regards to the former, BRATA has historically been circulated through SMS messages that mimic messages from the target’s bank. Those messages contain a link that will install BRATA if the victim opens it. The updated BRATA, on the other hand, has been left sitting on webpages that are designed to look like a real banking website to phish for additional clicks.

On the harvesting front, the enhanced BRATA (which was initially developed as spyware before morphing into a trojan) can ask users to switch from their phone’s default messaging app to a new one that remains under the fraudster’s control. That allows the fraudster to intercept any messages (including One-Time Passcodes) that come through. BRATA also lets fraudsters obtain device management permissions, gather GPS location data, and install a secondary piece of malware that logs events on the victim’s phone.

The mutated BRATA was discovered by a team of researchers from the Italian cybersecurity firm Cleafy. In addition to BRATA, they warned that there is another piece of malware that has some of the same code that seems as if it was built to collect contact information from an infected device. BRATA itself has primarily been used to target customers of banks in Brazil, the UK, and Spain, though the people using it are only targeting a single financial institution at a time. The fraudsters move on once that financial institution starts to implement stronger fraud prevention measures, but may circle back later with more sophisticated malware.

BRATA is not the only banking trojan that has emerged out of the Brazilian market. Security experts recently warned about new MaliBot malware that can bypass MFA security. 

Source: ZDNet

Filed Under: Industry News Tagged With: BRATA, Brazilian Remote Access Tool Android, Cleafy, cybersecurity, hack attacks, malware, mobile security, OTP security, phishing, Trojan horse attacks

Related News & Articles

Signicat Expands Reach with New Partners and New API

Tokyo-based MoriX to Develop Biometric Payment Cards Featuring T-Shape Sensor

FIDO Shares Full Agenda for Authenticate 2020

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • NordPass, Yahoo! Japan, and Regula Keep Up Mobile Biometrics Momentum
  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework
  • Transatlantic Digital Traveler Identity Project Gets High-Profile Tech Partner
  • Digital Identity Tech Demo Online Event

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld