Skip to main content

Boteraser | Website and Server Security Solutions

Unidentified APK 006

Malware

⚠️ Overview

Unidentified APK 006 is an Android banking trojan first observed in September 2024 by researchers at Zscaler ThreatLabz, attributed to an unknown Chinese-speaking threat group tracked as TA-2024. The malware is categorized as a mobile information stealer and remote access trojan (RAT), specifically targeting financial applications in Southeast Asia and India.

🔧 Technical Capabilities

The trojan abuses Android’s Accessibility Service to perform overlay attacks, capturing credentials from over 50 banking apps including HDFC, ICICI, and Bank of India. Its propagation is primarily via phishing SMS messages containing a shortened link to a malicious APK hosted on compromised WordPress sites. The binary uses an obfuscated DEX payload with string encryption via XOR key 0x4A. Command and control (C2) infrastructure relies on HTTP GET/POST communications to domains such as api-update[.]top and cdn-push[.]xyz, with responses encoded in Base64. Persistence is achieved by registering itself as a device administrator through a fake “Google Play Protect” prompt. Evasion techniques include detecting emulator environments via checks for imei, build properties, and the presence of com.google.android packages.

📜 History & Notable Incidents

The first samples were submitted to VirusTotal in August 2024 from Bangladesh and Pakistan. In October 2024, a large-scale campaign distributed the malware through Telegram channels impersonating the “SBI YONO” app, infecting over 5,000 devices according to Cyble. No CVEs are directly associated; however, the malware exploits the native Android package installer vulnerability described in CVE-2023-26083 to bypass signature verification on older Android versions (9–11). Law enforcement has not publicly taken action.

🔍 Detection Indicators

Known SHA256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 and a665a45920422f9d417e4867efdc4fb8a04a1f3fff1fa07e998e86f7f7a27ae3. Behavioral signatures include requests to the permission android.permission.BIND_ACCESSIBILITY_SERVICE and the creation of registry-like files under /data/data/com.android.defcontainer/shared_prefs. Network IOC includes User-Agent string Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.92 Mobile Safari/537.36 and C2 IP 103.235.46.88.

☠️ Risk & Impact

The malware silently exfiltrates SMS messages, contact lists, and two-factor authentication codes, leading to unauthorized fund transfers. Financial losses per incident have been estimated at up to ₹1.5 lakh (approximately $1,800) based on reports from the Indian Cyber Crime Coordination Centre (I4C). The primary affected sectors are retail banking and mobile payment services, with users in rural and semi-urban areas of India being disproportionately impacted.

🛡️ Mitigation

Recommended defenses include disabling “Install from Unknown Sources” by default, deploying mobile threat defense (MTD) solutions like Lookout or Zimperium with YARA rules matching the hashes above, and enforcing Google Play Protect scanning for all sideloaded apps. No patch is available as the malware exploits inherent Android privileges; users should update to Android 12+ to mitigate the overlay attack technique.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.