Security researchers have detected a new Android banking malware. This malware can steal information from almost 337 apps. In these apps, there come Amazon, Facebook and Tinder etc. The new Android malware is known as BlackRock. This security threat was discovered by the cybersecurity firm ThreatFabric. It is also detected that this new malware has links to other malware attacks. If you want to stay safe from the attack of this malware, you should stay safe by using the best antivirus software. You should try to use the best VPN service. According to security researchers, the source code of this malware attack was just similar to the source code of Xerxes malware.

How Does It Work?

After getting access to your device, this malware attack wants to hide its identity. It means that this malware attack is invisible to the end-users. While remaining invisible, it asks the victims for the privileges of the Accessibility Service. For this reason, it sends fake updates on your device. Most importantly, this essential malware can send fake Google updates to your device. Accepting these updates means that you are giving access to the requested Accessibility Service privileges to this malware attack. After getting access to the Accessibility Service privileges, this malware can get additional permissions from your device. This malware attack gets these permissions without getting any interaction with the users. After functioning its bots on your device, this malware receives commands from the server. As a result, hackers can perform the required tasks on your android phone.

How Do You Get It?

BlackRock malware is detected on the third-party website and appears in the form of Google updates. This essential app is found on the Google Play Store. Therefore, it can enter your device through Google’s app review process. Therefore, you should be aware of the apps you are coming across on Google. There is a bottom line about this malware attack. Its reason is that most of us think that if an app is present on the Google Play Store, it is a legitimate app. Therefore, we download it without investigating it. If you want to save your device from malware attacks, you should not download the apps even from the Google Play Store without investigating them.

Dangerous Abilities Of Blackrock Malware:

As we have discussed earlier, this malware attack can get various permissions from your device. After getting permissions on your device, this malware attack can perform many tasks on your device. According to security experts, if you want to render this malware using antivirus software, this malware also makes this rendering useless. The most dangerous abilities of this malware attack are explained below;

  • It can use your device for overlaying.
  • It can also use your device for keylogging.
  • It can involve your device in two kinds of SMS harvesting. These two kinds are SMS listing and SMS forwarding.
  • The hackers can use this malware attack to collect useful information from your device.
  • The hackers can also use this malware attack to send messages.
  • The hackers can also use it for remote actions like screen locking.
  • This essential malware attack has a self-protection ability. It means that it can hide the app icon, and it can also prevent app removal.
  • It can collect important notifications on your device and sends these notifications to hackers.
  • It can get various permissions on your device.
  • It also has the ability of AV protection.

The most alarming impact of this app is that it can harvest account information like username and passwords from your device. For this reason, they use a method known as overlays. With the help of this method, the hackers can encourage the users to reveal their credit card information from their devices. BlackRock android malware uses overlays for various purposes. This method can steal information from various apps like messaging, business, finance, social media, and much more. This essential Trojan is not active on the Google Play Store. Anyhow, it is available as spoofed Google updates on third-party updates. If you want to protect yourself from the attack of this malware, you should try to download the apps from reputable resources only. While downloading the apps from reputable resources, you should make sure that these apps are legitimate.

For this reason, you should read the reviews of the users. You should get an idea about the permissions of this app. You should also use unique passwords on the accounts.

Profiling:

Android work profiling is the unique property of this malware attack. Companies use this essential feature. The companies are using this feature as DPC (Device Policy Controller). With the help of DPC, the companies can control and apply policies to the mobile fleet. This essential feature allows the companies to access the various aspects of the information without the administration rights of the device. BlackRock malware is also using this technique. For this reason, it can create such a profile which can get access to the admin privileges.

The Lokibot Malware Family:

As we have discussed earlier, the BlackRock malware's source code is similar to the Xerxes banking trojan. Therefore, this essential android malware connects with the LokiBot malware family. First, this LokiBot malware was detected at the end of 2016. Its source code was revealed in 2018. After the detection of this malware, it was banned from the forums. It is expected that the BlackRock android malware also has the source code of the LokiBot malware family. Anyhow, some upgrades are made to this android malware. Therefore, this malware attack can properly work on newer android devices.

Moreover, this malware attack also uses new techniques to steal private information from android devices.  The hackers have enhanced it with accessibility features. Moreover, they have also included automated scripts in it.

Author Bio:

Susan Wray is a professional author based in Manchester. She has completed her Bachelor's Degree in Economics from the University of Manchester. She is currently living in the UK and working as a content writer at CheapEssayWritingUK. Her job role allows her to provide students with unique, high-quality, and inspiring dissertation writing services on any subject. She loves to address dissertation writing issues related to the different subjects in her blogs.