Android malware BRATA | Update | Secure your device Now!! - InfoCode World Android malware BRATA | Update | Secure your device Now!!

Android malware BRATA | Update | Secure your device Now!!

 

 
The Android malware called BRATA is introducing new harmful features to the latest version, which includes GPS monitoring, ability to utilize several communication options, as well as an option that performs an unintentional factory reset of the device, which erases any trace of malware.
BRATA was first identified by Kaspersky in the year 2019. It was an Android-based ARAT (remote access software) which primarily targeted Brazilian users.

The report was published in December of 2021. a publication from Cleafy highlighted the growing presence of malware in Europe in which it targeted the users of e-banking, and then stealing their passwords through the help of fraudsters pretending to be bank customer service agents.

Analysts from Cleafy continue to watch BRATA for the development of new features and in a report released today, they show how the malware is continuing to develop.

New features


The latest features discovered from Cleafy research team members in most recent BRATA versions have keylogging capabilities and a screen capture function. screen-capturing feature.

While its purpose is unknown to the experts, all the new models include GPS tracking.

The most frightening of the latest malware features is the execution of factory resets. This is something is performed by actors in the following scenarios:

The compromise was carried out successfully and the fraudulent transaction has been concluded (i.e. credentials have been removed).
The application has found that it is running in the virtual world, which is likely to be used to perform analysis.

BRATA utilizes factory resets to kill switches to safeguard itself. However, since they erase off the entire device they present the risk of a sudden and irreparable loss of information to the person who is victimized.

BRATA is introducing new channels of communication to exchange of information using the C2 server. The server now can support HTTP as well as WebSockets.

The choice of WebSockets allows the actors to use an immediate and low-latency channel which is perfect for real-time communication as well as live manual exploitation.

Additionally, since WebSockets does not require sending headers on every connection, the amount of network traffic that could be considered suspicious is minimized as well as, consequently the likelihood to be detected is reduced.

BRATA is just one of the Android banking trojans and sneaky RATs that are out there that target bank accounts of users.

The best method to avoid getting infected with Android malware is to download applications that are available on Google Play Store. Google Play Store, avoid APKs that are downloaded from untrusted websites, and test them using an antivirus tool prior to opening.

During the process of installation, pay careful focus on the permissions requested and do not grant permissions that are not necessary for the application's main functions. 


Comments