Keeping yourself safe online is increasingly challenging, and even reputable password managers can fall victim to hackers. Unscrupulous individuals who are too lazy to develop their own exploits from scratch can even use more convenient solutions such as MaaS (Malware-as-a-Service) to spread malware and infect other people’s devices. Security researchers have discovered a MaaS called Nexus that uses a Trojan to steal users’ banking and financial data from Android devices.

A new Android bot Trojan is here to steal your banking and financial data
Cybersecurity company Cleafy Sample data from underground forums were used to analyze Nexus’ modus operandi. The botnet, first discovered in March last year, allows unscrupulous actors to conduct ATO attacks for a fee of $3,000 per month. Nexus packages malicious Trojans into your Android with legitimate-looking, legitimate-looking apps inside suspicious third-party apps. Once a user’s device is infected, it immediately becomes part of a botnet controlled by hackers.

Nexus is a powerful malware capable of keylogging to record your passwords in various applications. It can also steal SMS-provided two-factor authentication (2FA) codes and information from the relatively secure Google Authenticator app, all without your knowledge. Malware can steal code to delete 2FA SMS, update automatically in the background, and distribute other malware. Because the victim device is part of a botnet, threat actors using Nexus can remotely monitor all bots (infected devices) and the data collected from them using a simple web panel. The interface reportedly allows customization of Nexus and supports remote injection of approximately 450 legitimate-looking banking application login pages to steal credentials.


Technically, Nexus is a mutation of the mid-2021 SOVA banking Trojan. Although Cleafy says the former appears to still be in beta development, SOVA’s source code has been stolen by Android botnet operators who also leveraged popular older MaaS. The stolen source code was exploited when running Nexus, and other malicious modules were added, such as ransomware, etc., which can lock users out of the device through AES (fortunately this part seems to be inactive at the moment).

Due to the Trojan-like nature of this malware, it can be difficult to detect on Android devices, but you may be aware of some obvious red flags and see unusual spikes in mobile data and Wi-Fi usage, which usually indicate that the malware is communicating with a hacked device or updating in the background.当设备未处于活动使用状态时,异常的电池消耗也可能是恶意软体引发后台活动的明显迹象。如果发现任何问题,建议在备份重要档案后将设备恢复原厂设置,或联系合格的网路安全专家。 To protect your Android device from dangerous malware like Nexus, always download apps from reputable sources, such as the Google Play Store. Additionally, make sure you’re running the latest available security updates and only grant apps authorizations that are critical to their operation. Apps like gallery or photo retouching apps shouldn’t need access to your call logs.
Source: KOCPC Chinese