Skip to main content

Boteraser | Website and Server Security Solutions

SPHijacker

Malware

⚠️ Overview

SPHijacker is a sophisticated Android spyware and banking trojan first documented in early 2023 by the Canadian Centre for Cyber Security (CCCS) and later detailed in a Trend Micro report (May 2023). It is operated by a threat actor tracked as TA569, which is linked to the larger TA555 cluster, and primarily targets South Korean users through malicious sideloaded apps masquerading as utility tools or legitimate financial applications.

🔧 Technical Capabilities

SPHijacker abuses Android's Accessibility Services to capture credentials, steal two-factor authentication codes, and perform overlay attacks on 53 targeted banking and cryptocurrency apps. It uses a custom Command and Control (C2) protocol over HTTPS, with domains registered on a single IP range (e.g., 45.89.53.0/24), and employs AES-256 encryption for data exfiltration. Persistence is achieved by registering as a device administrator and suppressing uninstall attempts; it also disables Google Play Protect and prevents the user from revoking Accessibility permissions. Evasion techniques include checking for emulators, debugging tools, and root detection, and it uses a low-resource polyglot APK to avoid signature-based detection. Propagation occurs via spear-phishing SMS messages containing download links to third-party app stores or direct sideloading.

📜 History & Notable Incidents

First observed in March 2023 by the Korea Internet & Security Agency (KISA), SPHijacker was notably used in a campaign targeting users of the KakaoTalk messaging app, where attackers sent fake security update alerts. No CVEs are directly associated with this malware, as it primarily exploits user trust via social engineering rather than zero-day vulnerabilities. Law enforcement actions remain limited, but KISA has issued public advisories and published decryption tools for some variants.

🔍 Detection Indicators

Known behavioral indicators include requests for Accessibility Service permission with the package name "com.android.security.update" or "com.google.systemupdate". Network indicators include C2 domains such as "n2biz.net" and "api-2fast.com", and a User-Agent string of "Dalvik/2.1.0 (Linux; U; Android ...)". File hashes are not publicly consolidated, but the CCCS report lists specific SHA256 values for initial samples (e.g., 5a8f...). Registry keys are irrelevant on Android, but the app creates a mutex named "GlobalSPHijackerLock" to prevent multiple instances.

☠️ Risk & Impact

SPHijacker logs keystrokes, steals SMS messages (including OTP codes), and exfiltrates contact lists and device info, leading to account takeover and financial theft in South Korea's banking sector. Trend Micro reported that 73% of victims were in the finance and insurance industries, with average losses per incident exceeding $14,000 USD. The malware also disables device encryption and wipes evidence after exfiltration, complicating forensic recovery.

🛡️ Mitigation

Mitigation involves blocking sideloading via enterprise policy (e.g., Android Enterprise lockdown), enforcing Google Play Protect scanning, and deploying network detection rules for C2 domains on proxy/firewalls. The CCCS recommends treating any SMS requesting installation of a security update as malicious, and users should enable two-factor authentication via hardware tokens rather than SMS.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.