Threat Intelligence Brief
Curated summary with source attribution
Source: ibm.com
Threat Risk: High
Victim: Android mobile banking users
Incident: Deployment of the GoldDigger banking Trojan to commit on-device financial fraud.
Impact: Unauthorized access to banking credentials and theft of funds from target accounts.
Attacker: Unidentified threat actors
Analysis: GoldDigger employs a custom packer called ‘dpt-shell’ and hooks the Android Runtime (ART) library to manipulate bytecode on the fly. This allows the malware to conceal its malicious classes from static analysis and antivirus software. By utilizing a virtualized environment, it executes fraudulent transactions while remaining virtually invisible to traditional security monitors.
Recommendations: Enable multi-factor authentication (MFA) using non-SMS methods for banking apps; Avoid sideloading Android applications from unofficial third-party sources; Keep Android OS and security patches up to date to mitigate runtime library exploits
Source: IBM Trusteer
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source