Palo Alto Networks has recently discovered 22 Android apps belonging to a new Trojan family called ‘Xbot’. It is capable of stealing victims’ banking credentials and credit card information. It can also remotely lock infected Android devices. This Android Trojan is regularly updated and is already capable of multiple malicious behaviors.
So far, in Asia-Pacific, only users in Australia have been targeted, along with Android users in Russia, elsewhere in the world. Importantly, of the seven bank apps Xbot seen to imitate, six belong to some of the most popular banks in Australia.
So how does Xbot attack its victims’? Xbot primarily uses is a popular attack technique called “activity hijacking” by abusing some features in Android. The apps Xbot is mimicking are not themselves being exploited. Starting with Android 5.0, Google adopted a protection mechanism to mitigate this attack but other attack approaches used by Xbot are still affecting all versions of Android.

While Android users running version 5.0 or later are so far protected from some of Xbot’s malicious behaviors, all users are vulnerable to at least some of its capabilities. As the creator appears to be putting considerable time and effort into making this Trojan more complex and harder to detect, it’s likely that its ability to infect users and remain hidden will only grow, and that the attacker will expand its target base to other regions around the world.
Palo Alto Networks researchers observed the author making regular updates and improvements indicating that this malware could soon threaten Android users across the world.



