Rana
Malware⚠️ Overview
Rana is an Android banking trojan first documented in May 2020 by Cyble’s research team, attributed to a threat actor likely operating out of South Asia. It belongs to the category of mobile financial malware, specifically designed to steal credentials and intercept SMS-based two-factor authentication from banking and payment applications. Its primary targets are users of Indian banks, including State Bank of India, HDFC Bank, and ICICI Bank, though variants have been observed targeting other financial institutions globally.
🔧 Technical Capabilities
Rana achieves initial infection through social engineering campaigns, typically masquerading as a legitimate app such as a banking utility, loan application, or system update, distributed via third-party app stores or phishing links. Once installed, it requests extensive permissions, including Accessibility Service access, which allows it to read screen contents and perform overlay attacks to capture login credentials. The malware maintains persistence by disabling Google Play Protect and hiding its icon from the app drawer. Its command-and-control (C2) infrastructure uses HTTP/HTTPS to exfiltrate stolen data, including SMS messages, contact lists, and app account details. Evasion techniques include obfuscated code through ProGuard and runtime checks for emulators or security tools. It can also intercept and forward SMS messages to the C2 server, effectively bypassing SMS-based one-time passwords.
📜 History & Notable Incidents
First identified in May 2020 by Cyble, Rana was observed in a targeted campaign against Indian banking customers, with the malware being distributed under the guise of a loan app named "Loan Easy". A subsequent variant in 2021 incorporated new phishing overlays for additional Indian banks and was tracked by Quick Heal Security Labs. No specific CVEs are attributed to Rana, as it relies on user-granted Accessibility permissions rather than exploiting system vulnerabilities. Law enforcement actions are not publicly documented, but the malware remains active in targeted, low-volume campaigns.
🔍 Detection Indicators
Indicators of compromise (IOCs) for Rana include the package name com.rana.loaneasy (or similar) and the application icon depicting a generic bank or loan symbol. Behavioral indicators include requests for Accessibility Service activation, SMS reading permissions, and unusual network connections to IP addresses associated with Indian hosting providers. Hardcoded C2 domains such as ranac2[.]pro have been reported by Cyble.
☠️ Risk & Impact
Rana primarily causes financial loss by stealing banking credentials and bypassing two-factor authentication, enabling unauthorized fund transfers. The malware also exfiltrates personal data, including contact lists and SMS contents, which can be used for identity theft or further phishing campaigns. Affected sectors are predominantly retail banking and digital payment services in India, with potential impact on individual account holders.
🛡️ Mitigation
Mitigation measures include installing applications only from the official Google Play Store, enabling Google Play Protect, and avoiding granting Accessibility permissions to apps with suspicious behavior. Organizations should implement mobile device management (MDM) policies and deploy behavioral detection rules, such as those provided by Cyble’s threat intelligence reports, to identify unauthorized Accessibility Service activations and SMS interception attempts.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.