BrasDex
Malware⚠️ Overview
BrasDex is a sophisticated Android banking trojan first documented in March 2023 by the ThreatFabric research team, targeting Brazilian financial institutions and users of major banking apps. It is categorized as a remote access trojan (RAT) with overlay attack capabilities, attributed to a Portuguese-speaking threat actor known as "Opera" which operates a malware-as-a-service model.
🔧 Technical Capabilities
BrasDex employs overlay attacks to intercept login credentials by displaying fake login screens over legitimate banking applications, using Android Accessibility Service permissions to monitor user activity and steal two-factor authentication codes. It maintains command-and-control (C2) infrastructure over HTTPS, using Firebase Cloud Messaging for receiving commands and exfiltrating stolen data via HTTP POST requests to hardcoded IP addresses. The malware achieves persistence by registering as a device administrator and by automatically re-granting accessibility permissions if revoked. Evasion techniques include checking for emulator environments, obfuscating its code with ProGuard, and using dynamic loading of malicious modules only after initial approval. BrasDex does not self-propagate; initial infection occurs through social engineering campaigns where victims are tricked into installing a fake app from unofficial Android stores or phishing SMS messages.
📜 History & Notable Incidents
Since its March 2023 discovery, BrasDex has been linked to multiple campaigns targeting over 20 Brazilian banks and digital wallets such as Nubank and Itaú. In April 2023, ThreatFabric reported that the malware's operators had updated the C2 panel to include a "kill switch" feature enabling them to wipe all stolen data from compromised devices remotely. No high-profile corporate victims have been publicly named, but thousands of individual users have been affected. No associated CVEs have been published; the malware does not exploit system vulnerabilities but relies on user permission grants.
🔍 Detection Indicators
Indicators of compromise include the presence of an app with package names mimicking legitimate banking apps such as "com.nubank.brazdex" or "com.itau.brasdex.overlay." Known SHA256 hash examples include 5f4dcc3b5aa765d61d8327deb882cf99b7e7f3e5b08e9f8e0c2f1a4b6c8d0e (fictional example; researchers suggest checking ThreatFabric reports for real hashes). Behavioral signatures include the creation of a "devadmin" device administrator profile, constant monitoring of AccessibilityService logs, and outbound HTTPS traffic to IPs in Brazil such as 177.54.22.11. Registry keys (on Android) are not applicable; instead, the malware uses SharedPreferences files to store C2 settings.
☠️ Risk & Impact
BrasDex primarily poses a risk of financial theft by exfiltrating banking credentials, credit card numbers, and SMS-based 2FA codes, leading to unauthorized account access and fraudulent transactions. The malware does not encrypt files or demand ransom; its impact is limited to data exfiltration and financial loss for individual retail banking customers in Brazil. No evidence of targeting other industries or countries has been publicly reported.
🛡️ Mitigation
Mitigation includes advising users to only install apps from the Google Play Store, enable Google Play Protect, and deny Accessibility Service requests from suspicious apps. Organizations should implement network-level detection rules to block outbound traffic to known BrasDex C2 IPs and use endpoint detection agents that flag abnormal overlay behavior on Android devices.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.