Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Location-Based Gaming NFTs: How GPS and Blockchain Are Changing the Way We Play

May 2, 2026

ZachXBT Exposes US Law Firm Gerstein Harrow’s $71M Grab of Stolen Lazarus Funds

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Android Banking Trojan Zanubis Evolves to Target Peruvian Users
Android Banking Trojan Zanubis Evolves to Target Peruvian Users
Security

Android Banking Trojan Zanubis Evolves to Target Peruvian Users

September 28, 2023No Comments3 Mins Read

The Android banking Trojan Zanubis has taken on a new guise, posing as the official app for the Peruvian governmental organization SUNAT (Superintendencia Nacional de Aduanas y de Administración Tributaria). 

Originally detected in August 2022, this malware targets financial and cryptocurrency users in Peru by impersonating legitimate Android apps. Zanubis tricks users into granting Accessibility permissions, effectively surrendering control of their devices.

What sets Zanubis apart is its increasing sophistication, explained a new advisory published by Kaspersky today. The Trojan utilizes the Obfuscapk obfuscator for Android APK files, making it challenging to detect.

Once it gains access to a victim’s device, it deceives them by loading a genuine SUNAT website using WebView, creating the illusion of legitimacy. The Trojan maintains communication with its controlling server through WebSockets and a library called Socket.IO, ensuring connectivity even in adverse conditions.

What’s particularly worrisome is Zanubis’s adaptability. Unlike typical malware with fixed target apps, Zanubis can be remotely programmed to steal data when specific apps are in use. Additionally, it establishes a second connection, potentially granting malicious actors complete control over a compromised device. To compound the threat, it can disable a device by masquerading as an Android update.

In the same advisory, Kaspersky researchers mentioned the discovery of a cryptor/loader called AsymCrypt, designed to target crypto wallets and distributed through underground forums. This evolved DoubleFinger loader variant serves as a gateway to the TOR network. Buyers customize its functionality, injecting malicious DLLs concealed within encrypted image blobs.

The Lumma stealer is another evolving malware lineage recently discovered by the security researchers. Previously known as Arkei, Lumma retains 46% of its original attributes. To infect a system, this malicious software camouflages itself as a file converter from .docx to .pdf, triggering its payload when files come back with a double extension of .pdf.exe.

See also  Massive Android Vulnerability Left Millions Of Crypto Wallets Exposed to Hackers

Lumma primarily targets crypto wallets, stealing cached files, configuration files and logs. Its evolution includes system process list acquisition, altered communication URLs and advanced encryption techniques.

Read more on crypto-stealers: Satacom Malware Campaign Steals Crypto Via Stealthy Browser Extension

Tatyana Shishkova, a lead security researcher at Kaspersky’s GReAT (Global Research and Analysis Team), emphasized the dynamic nature of these threats and the importance of staying informed. 

“The ever-evolving landscape of malware, exemplified by the multifaceted Lumma stealer and the ambitions of Zanubis as a full-fledged banking Trojan, underscores the dynamic nature of these threats,” she said.

“Intelligence reports play a pivotal role in keeping abreast of the latest malicious tools and attacker techniques, empowering us to stay one step ahead in the ongoing battle for digital security.”

Kaspersky recommended various preventive measures, including offline backups, anti-ransomware tools and dedicated security solutions, to mitigate financially motivated threats.

Source link

Android Banking Evolves Peruvian Target Trojan users Zanubis

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026

Tax season fuels rise in crypto wallet scams, Kaspersky reports

May 2, 2026
Top Posts

Maison Margiela: Entering the Web3 Era with Gamified Minting

October 26, 2023

Inflation takes center stage: Crypto Week Ahead

April 6, 2026

Modular network Celestia goes live on mainnet

October 31, 2023

Type above and press Enter to search. Press Esc to cancel.