android, banking trojan, malware, ransomware, sova, android

The SOVA Android banking trojan continues to evolve with new features, code improvements, and the addition of a new ransomware feature that encrypts files on mobile devices.

With the latest release, the SOVA malware now targets over 200 banking, cryptocurrency exchange, and digital wallet applications, attempting to steal sensitive user data and cookies from them.

Moreover, it features refactored and improved code that helps it operate more stealthy on the compromised device, while its latest version, 5.0, adds a ransomware module.

Rapid evolution

Threat analysts at mobile security firm Cleafy have followed SOVA’s evolution since the project’s announcement in September 2021 and report that its development has rapidly increased in 2022.

In March 2022, SOVA released version 3, adding 2FA interception, cookie stealing, and new injections for multiple banks worldwide. Injections are overlays shown over legitimate login prompts that are used to steal credentials, such as those for online bank apps.

In July 2022, SOVA’s development team released version 4, which took the targeted apps up to 200, and added VNC (virtual network computing) capabilities for on-device fraud.

android, banking trojan, malware, ransomware, sova, android

Bank apps targeted by SOVA v3 (left) and SOVA v4 (right) (Cleafy)

The malware sends a list of installed applications to the C2 and receives an XML containing a list of addresses that point to the correct overlays to be loaded when the victim opens a targeted app.

The fourth major version also added support for commands such as taking screenshots, performing clicks and swipes, copying and pasting files, and serving overlay screens at will.

This release also saw a significant code refactoring in the cookie stealer mechanism, now targeting Gmail, GPay, and Google Password Manager.

android, banking trojan, malware, ransomware, sova, android

Refactored cookie stealer code (Cleafy)

SOVA v4 added some protections against defensive actions, abusing Accessibility permissions to push the user back to the home screen if they attempt to uninstall the app manually.

Finally, the fourth version focused on Binance and the platform’s ‘Trust Wallet’ app, using a dedicated module created to steal the user’s secret seed phrase.

New ransomware module

More recently, Cleafy sampled an early release of SOVA v5, which comes with numerous code improvements and the addition of new features such as a ransomware module.

android, banking trojan, malware, ransomware, sova, android

SOVA’s new ransomware module (Cleafy)

The module uses AES encryption to lock all files in infected devices and append the “.enc” extension on the renamed, encrypted files.

“The ransomware feature is quite interesting as it’s still not a common one in the Android banking trojans landscape. It strongly leverages on the opportunity arises in recent years, as mobile devices became for most people the central storage for personal and business data.” – Cleafy

The fifth version isn’t widely circulated yet, though, and its VNC module is missing from the early samples, so it’s likely that this version is still under development.

Even in its current, unfinished form, SOVA v5 is ready for mass deployment, according to Cleafy, so vigilance is advised to all Android users.

Finally, the malware’s author appears determined and capable of fulfilling their September 2021 promises, sticking to the development timeline and adding advanced features every few months.

This makes SOVA a threat of growing intensity, as the banking trojan is now setting itself as one of the pioneers of the still under-explored space of mobile ransomware.

TECH NEWS RELATED

2022 Hyundai Staria 10-seater Launched - 3 Variants, Lite, Plus and Max - Priced From RM180k

Hyundai-Sime Darby Motors(HSDM), the authorized distributor of Hyundai in Malaysia today announced the introduction of the 10-seater Staria, a more price-friendly version of the space-ship-inspired MPV. The Hyundai Staria which was first introduced into the local market back in October 2021 debuted as a premium 7-Seater MPV, but the 10-seater option ...

View more: 2022 Hyundai Staria 10-seater Launched - 3 Variants, Lite, Plus and Max - Priced From RM180k

The Seven Deadly Sins: Grand Cross celebrates 50 million downloads with new character, login bonuses and more

Netmarble is celebrating a whopping 50 million downloads for The Seven Deadly Sins: Grand Cross, its incredibly popular mobile gacha RPG on iOS and Android. In the “50 Million DL Celebration Festival”, players can expect a new hero, themed special events, lots of in-game rewards and more. In the ...

View more: The Seven Deadly Sins: Grand Cross celebrates 50 million downloads with new character, login bonuses and more

Missed buying Nothing Phone (1) during Big Billion Days? You Can Still Get It With Similar Offers on Flipkart

Nothing Phone (1) is available with up to Rs 7,000 discount in Flipkart's Big Dussehra Sale.

View more: Missed buying Nothing Phone (1) during Big Billion Days? You Can Still Get It With Similar Offers on Flipkart

2023 BMW XM Due in Australia First Half of 2023

After a concept preview and a long teaser campaign, BMW’s M Division has revealed its first bespoke car in 40 years: the 2023 BMW XM. Due in Australia in the first half of 2023, the XM is a V8 plug-in hybrid sports SUV that pumps out 480kW of power ...

View more: 2023 BMW XM Due in Australia First Half of 2023

5 iOS, Android Productivity Apps That are Helpful for Students

Being a student is not an easy task. There will be a lot of assignments and requirements to complete. There will be tons of materials to review and study. Amid all the coursework, there could be a lot of distractions. Now that we are in the age of social media, ...

View more: 5 iOS, Android Productivity Apps That are Helpful for Students

Spiritfarer lets players guide souls into the afterlife, out now on mobile via Netflix

Thunder Lotus, Playdigious and Netflix are officially bringing Spiritfarer to mobile, letting subscribers to the streaming service get their hands on the death-themed management game with no disruptive ads or pesky in-app purchases. The “cosy death-positive adventure” joins the budding lineup of games from Netflix where all players need ...

View more: Spiritfarer lets players guide souls into the afterlife, out now on mobile via Netflix

Moto E32 India Launch Date Set for October 7: Specifications and Everything We Know About

The Moto E32 will be powered by a MediaTek Helio G37 processor.

View more: Moto E32 India Launch Date Set for October 7: Specifications and Everything We Know About

2023 Toyota GR Supra pricing announced, manual due in November

UPDATE: Manual GR Supra in Australia from November The updated 2023 Toyota GR Supra, including the long-awaited manual option, will be on sale in Australia from November 10. Confirmation of a manual transmission for the new GR Supra came back in March, after months of speculation that the automatic offered ...

View more: 2023 Toyota GR Supra pricing announced, manual due in November

Redmi Pad Price in Malaysia & Specs

2023 Hyundai Ioniq 6 WLTP driving range ranks among best in class

Suzuki Jimny 5-door spied ahead of expected 2023 reveal

How to Change App Icon Size on Your Android Device

Linux kernel 5.19.12 can damage Intel laptop LCDs

2023 Toyota Corolla: Australian details revealed

Today’s Wordle Answer (October 5th, 2022): Puzzle 473 Hints, Clues, and Solution

Minecraft Devs Reveal a Cute Ancient Mob as First Candidate for Popular Vote

2023 CB750 HORNET RELEASED

New Renault Megane E-Tech 2022 review

Vauxhall Combo, Vivaro and Movano vans get a range revamp with Prime and Pro models

10 Best TikTok Video Downloaders in 2022

OTHER TECH NEWS

Top Car News Car News