Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Steel Power Unveiled: Is SteelPower Male Enhancement Formula Legit? Read Steel Power Supplement Report!

May 2, 2026

Seoul Court Rescues Bithumb from Record 6-Month Suspension

May 2, 2026

Bitdeer Sells All Mined BTC This Week: Zero-Holding Strategy Intensifies

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»New Android Banking Trojan ‘Nexus’ Promoted As MaaS
New Android Banking Trojan 'Nexus' Promoted As MaaS
Security

New Android Banking Trojan ‘Nexus’ Promoted As MaaS

October 5, 2023No Comments2 Mins Read

A new Android banking Trojan has been discovered in several malicious campaigns worldwide. Dubbed ‘Nexus’ by Cleafy security researchers, the tool is promoted as part of a Malware-as-a-Service (MaaS) subscription and provides features to perform account takeover (ATO) attacks.

“In January 2023, a new Android banking Trojan appeared on multiple hacking forums under the name of Nexus,” wrote the company in an advisory published on Tuesday. “However, [we] traced the first Nexus infections way before the public announcement in June 2022.”

Analysing Nexus samples last year, Cleafy noticed code similarities between the malware and SOVA, an Android banking trojan discovered in mid-2021. At the time, the team believed Nexus to be an updated version of SOVA.

“Despite the new MaaS program launched under the name Nexus, the authors may have reused some parts of SOVA internals to write new features (and rewrite some of the existing ones),” explained Cleafy.

“Recently, the SOVA author, who operates under the alias ‘sovenok,’ started sharing some insights on Nexus and its relationship with SOVA, calling out an affiliate who previously rented SOVA for stealing the entire source code of the project.”

Regarding features facilitating ATO operations, Nexus offers overlay attacks and keylogging activities designed to steal victims’ credentials. It can also steal SMS messages (to obtain two-factor authentication codes) and information from cryptocurrency wallets.

Read more on banking trojans here: Researchers Discover Nearly 200,000 New Mobile Banking Trojan Installers

“Nexus is also equipped with a mechanism for autonomous updating,” Cleafy wrote. “A dedicated function asynchronously checks against its C2 server for updates when the malware is running.”

See also  DOJ seizures of $580M expose how crypto investment scams scaled into shift work with quotas and scripts

The malware also includes a module capable of encryption, possibly ransomware.

“This module seems to be under development due to the presence of debugging strings and the lack of usage references,” the company clarified.

More generally, Cleafy said that the absence of a virtual network computing (VNC) module (that would allow for remote access) currently limits the action range and capabilities of Nexus.

“However, according to the infection rate retrieved from multiple C2 panels, Nexus is a real threat that is capable of infecting hundreds of devices around the world,” the security team warned. “Because of that, we cannot exclude that it will be ready to take the stage in the next few months.”

Source link

Android Banking MaaS Nexus Promoted Trojan

Related Posts

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026

Crypto industry backs CLARITY Act yield compromise, pushes Senate Banking for markup

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026
Top Posts

First Mover Americas: Ether ETFs Struggle to Gain Traction in First Week

October 7, 2023

Gotbit’s fake trades haunt Cere as $157m suits hit Lime chair

April 12, 2026

From Cathie Wood to Cantor Fitzgerald, the big money is betting that Robinhood’s crypto slump is just a temporary speed bump

April 30, 2026

Type above and press Enter to search. Press Esc to cancel.