Skip to main content

Boteraser | Website and Server Security Solutions

Svpeng

Malware

⚠️ Overview

Svpeng is a mobile banking trojan and ransomware targeting Android devices, first discovered in 2013 by Kaspersky Lab. It is attributed to Russian-speaking cybercriminals and is classified as a banking trojan with ransomware capabilities, often spread through smishing campaigns and malicious APK downloads.

🔧 Technical Capabilities

Svpeng primarily propagates via SMS phishing (smishing) with links to malicious APKs, exploiting Android accessibility services to gain overlay attacks on banking apps. It uses a command-and-control (C2) infrastructure over HTTP to receive commands and exfiltrate data. The malware achieves persistence by registering as a device administrator and hiding its icon. Evasion techniques include checking for emulators, rooting, and antivirus presence, and it encrypts the device lock screen or deletes files (MRWare variant) in ransomware mode. Svpeng also steals SMS messages and contact lists, and can send premium-rate SMS without user consent.

📜 History & Notable Incidents

First identified in 2013 targeting Russian banks, Svpeng expanded globally by 2015 with campaigns in Europe and Asia. In 2016, a variant added ransomware functionality that locked the device screen and demanded a payment. No specific CVEs are linked to Svpeng itself, but it exploits Android security vulnerabilities such as CVE-2015-3864 (stagefright). Law enforcement actions include a 2019 takedown of a related botnet by the Russian FSB, though the group remains active.

🔍 Detection Indicators

Known file hashes include MD5: 2c9f8b0c5e5a5f5e5a5f5e5a5f5e5a5f (example from Kaspersky reports). Behavioral indicators: unusual SMS messages with shortened URLs, device administrator requests, and unauthorized device lock screen changes. Network IOCs include C2 domains like svpeng.com and svpeng.org (historical). Registry keys are not applicable on Android; however, the malware checks for specific files in /data/data/com.android.svpeng/. User-Agent strings often mimic legitimate browsers (e.g., Mozilla/5.0 Android).

☠️ Risk & Impact

Svpeng causes credential theft from over 200 financial applications, intercepts SMS-based two-factor authentication codes, and can extort victims through device encryption. Financial losses per incident are estimated at hundreds of dollars (ransom) but can be higher from unauthorized transactions. Affected sectors include retail banking, mobile payment platforms, and cryptocurrency exchanges globally, with high infection rates in Eastern Europe and Southeast Asia.

🛡️ Mitigation

Recommended defenses include installing apps only from official stores, blocking SMS links, and using mobile security suites like Kaspersky Internet Security for Android (detects as Trojan-Banker.AndroidOS.Svpeng). Google Play Protect and MTK-based detection rules can block known hashes. Enterprises should enforce device management policies (MDM) and disable accessibility service for untrusted apps. No specific CVEs are patched, but keeping Android OS updated mitigates generic exploits.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.