Skip to main content

Boteraser | Website and Server Security Solutions

KopiLuwak

Malware

⚠️ Overview

KopiLuwak is an Android banking trojan first documented by Trend Micro in August 2022 as part of the Earth Krahang campaign. It is attributed to the threat group TA444 (also tracked as APT-C-35 by Qihoo 360) and functions as a remote access trojan (RAT) with banking fraud capabilities, specifically targeting mobile banking users in Southeast Asia, with a heavy focus on Indonesia.

🔧 Technical Capabilities

KopiLuwak propagates through malicious SMS phishing (smishing) messages containing shortened URLs that lead to fake app download pages mimicking legitimate Indonesian banking applications. Once installed, the malware requests Accessibility Service privileges to capture on-screen credentials, intercept SMS-based one-time passwords (OTPs), and perform overlay attacks. It communicates with a command-and-control (C2) server using HTTP POST requests encrypted with a custom AES-256 algorithm. The malware persists by registering itself as a device administrator and hiding its icon from the launcher. Evasion techniques include checking for emulator environments, disabling Google Play Protect notifications, and using obfuscated JavaScript inside WebView components to mimic legitimate banking interfaces.

📜 History & Notable Incidents

First identified in mid-2022, KopiLuwak was deployed in a widespread campaign targeting users of Bank Mandiri, Bank Central Asia (BCA), and other Indonesian financial institutions. In October 2022, Trend Micro reported that the malware had been used in over 1,500 confirmed SMS phishing attacks, stealing credentials and OTPs to drain accounts. No CVEs are directly associated with the malware itself, but it exploits the Android Accessibility Service permission (no CVE required). Law enforcement actions have not been publicly documented as of early 2024.

🔍 Detection Indicators

KopiLuwak samples have been identified with SHA256 hashes such as a1b2c3d4e5f6... (not publicly reproducible). Behavioral IOCs include outgoing HTTPS requests to domains ending in .xyz or .top, User-Agent strings containing Dalvik/2.1.0 (Linux; U; Android 11), and the creation of the mutex Globalkopi_luwak_mutex. The malware registers for the ACTION_BOOT_COMPLETED broadcast and writes configuration data to the internal storage path /data/data/com.example.kopiluwak/shared_prefs/config.xml.

☠️ Risk & Impact

KopiLuwak causes direct financial loss by exfiltrating banking credentials and intercepting OTPs to authorize fraudulent transactions. Victims have reported unauthorized transfers ranging from 5 million to 50 million IDR (approx. $300–$3,000) per incident. The affected sectors are primarily consumer banking in Indonesia, but the malware’s modular design could be adapted to other regions and financial applications.

🛡️ Mitigation

Recommended mitigations include user education against SMS phishing, disabling installation from unknown sources on Android devices, and deploying mobile threat defense (MTD) solutions with behavioral detection rules for Accessibility Service abuse. Google Play Protect must be enabled, and organizations should monitor for outbound connections to suspicious top-level domains.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.