Nexus Android Trojan

General News

Summary

However, the Trojan provides all the necessary features to conduct Account Takeover (ATO) attacks against banking portals and cryptocurrency services, such as stealing login credentials and intercepting SMS messages. The malicious capabilities of Nexus make it a sophisticated and dangerous banking trojan that can cause significant financial damage to its victims. However, there is proof to suggest that the trojan may have already been deployed in real-world attacks as early as June 2022, at least six months prior to its official announcement on the darknet portals. Interestingly, the authors of Nexus have set explicit rules prohibiting the use of their malware in several countries, including Azerbaijan, Armenia, Belarus, Kazakhstan, Kyrgyzstan, Moldova, Russia, Tajikistan, Uzbekistan, Ukraine, and Indonesia. Moreover, the malware has been enhanced with new functionalities, such as the ability to remove received SMS messages, activate or deactivate the 2FA stealer module, and update itself by periodically communicating with a command-and-control (C2) server.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M