{"id":1356,"date":"2023-08-28T07:23:31","date_gmt":"2023-08-28T07:23:31","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1356"},"modified":"2024-04-22T12:50:40","modified_gmt":"2024-04-22T12:50:40","slug":"trojan-android-wroba-roamingmantis","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2023\/08\/28\/trojan-android-wroba-roamingmantis\/","title":{"rendered":"Trojan.Android.Wroba.Roamingmantis"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Trojan<\/p>\n<p><strong>Potential Damage<\/strong>: Medium<\/p>\n<p><strong>Prevalence:<\/strong> Medium<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Malware name(s)<\/strong><\/h3>\n<ul>\n<li>Trojan.Android.Wroba.Roamingmantis (Padvish)<\/li>\n<li>HEUR:Trojan-Dropper.AndroidOS.Wroba.o (Kaspersky)<\/li>\n<li>ANDROID\/Drop.Wroba.monhn (Avira)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3>What is a Trojan?<\/h3>\n<p>Trojan is a type of malware that disguise itself as cleaned and legitimate software and behaves totally like a useful and functional software. But when executed, it causes a lot of damage to the computer system.<br \/>\nThere are different ways in which trojans could enter the system, some are: Entering through a software downloaded from the Internet, embedding in HTML text, attaching to an email, etc.<\/p>\n<p>&nbsp;<\/p>\n<h3>What is the Wroba malware family?<\/h3>\n<p>Wroba malware family is a type of android banking Trojan and its main role is to intercept user&#8217;s text messages. So, this trojan can read incoming text messages containing one-time passwords (OTP) or other authentication codes. Therefore, bypassing 2FA implemented by banks is facilitated for Trojans.<\/p>\n<p>&nbsp;<\/p>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<ul>\n<li>Application&#8217;s icon Hiding<\/li>\n<li>Persistent notification bar<\/li>\n<li>Get dangerous permission to contacts and text messages<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3>How does it work?<\/h3>\n<p>Roaming Mantis ( also known as Shaoye) is a cyberattack campaign that distributes mobile malwares via smishing, through targeting Android devices.<br \/>\nSmishing is also a type of cyber-attack in which a malicious link is sent in a text message (SMS) that leads a person to a malicious website or a drive-by download onto their device.<br \/>\nIn fact, Roaming Mantis makes use of APK files to steal device information, and it makes use of phishing pages to steal victims&#8217; credentials or user accounts.<br \/>\nThe malware does this, by accessing Wi-Fi Router&#8217;s Settings and changing the DNS IP address (DNS Hijacking).<br \/>\nThis was previously implemented in the known Android malware Wroba.o\/Agent.eq, which was the main malware used in this campaign.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>CxActivity:<\/strong><\/p>\n<p>CxActivity is the main activity of the application. In onCreate it starts another activity called Ce.<\/p>\n<p>Cx activity, by asking the user to disable the battery optimization, helps the malware run its services without worrying about being closed by the operating system<br \/>\nThen, it stops running (closes) by calling the finish() function.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>IqApplication class:<\/strong><\/p>\n<p>Once the application is logged in, IqApplication class is executed, and loads functions from the ig.so file generally.<\/p>\n<p>The application makes use of functions use in ig.so file to read, decode and execute a file named b.dex.<br \/>\nFor example, one of its important functions is pi, which reads and decodes the file inside the asset folder.<\/p>\n<p><span class=\"HwtZe\" lang=\"en\"><span class=\"jCAhz ChMk0b\"><span class=\"ryNqvb\">Part of the pi function code.<\/span><\/span> <span class=\"jCAhz ChMk0b\"><span class=\"ryNqvb\">According to the figure, this piece of code reads a file from the asset folder:<\/span><\/span><\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1357\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/\u0639\u06a9\u0634-1-1.jpg\" alt=\"\" width=\"626\" height=\"202\" \/><\/p>\n<p>Part of the mz function code. According to the figure, this piece of code loads a dex file:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1358\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/2-\u0628\u062e\u0634\u06cc-\u0627\u0632-\u06a9\u062f-\u062a\u0627\u0628\u0639-mz..jpg\" alt=\"\" width=\"699\" height=\"185\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>b.dex file:<\/strong><\/p>\n<p>In this file, in the com.b class, first the Wi-Fi type and the address of the network router is found .<br \/>\nThe following two images show some parts of the x function that do this:<\/p>\n<p>Part of the codes of function x from class com.b:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1359\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/4-\u0642\u0633\u0645\u062a\u06cc-\u0627\u0632-\u06a9\u062f\u0647\u0627\u06cc-\u062a\u0627\u0628\u0639-x-\u0627\u0632-\u06a9\u0644\u0627\u0633-com.b.jpg\" alt=\"\" width=\"793\" height=\"197\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1360\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/5-\u0642\u0633\u0645\u062a\u06cc-\u0627\u0632-\u06a9\u062f\u0647\u0627\u06cc-\u062a\u0627\u0628\u0639-x-\u0627\u0632-\u06a9\u0644\u0627\u0633-com.b.jpg\" alt=\"\" width=\"592\" height=\"139\" \/><\/p>\n<p>After finding the Wi-Fi router&#8217;s address, based on the router configuration, a request is sent to it.<br \/>\nBut before this, the malware sends a request to an address by calling the w method of the com.b class and receives the dns server IP address. The address that is embedded in dns servers is:<\/p>\n<p>https:\/\/m[.]vk[.]com\/id728588947?act=info\u00a0(The address is not available in the time of writing this report)<\/p>\n<p>Setting dns server using the w function output:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1361\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/6-\u062a\u0646\u0638\u06cc\u0645-dns-server-\u0628\u0647-\u06a9\u0645\u06a9-\u062e\u0631\u0648\u062c\u06cc-\u062a\u0627\u0628\u0639-w.jpg\" alt=\"\" width=\"662\" height=\"256\" \/><\/p>\n<p>Function w of class com.b:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1362\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/7-\u062a\u0627\u0628\u0639-w-\u0627\u0632-\u06a9\u0644\u0627\u0633-com.b.jpg\" alt=\"\" width=\"962\" height=\"370\" \/><\/p>\n<p>Function p of class t:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1363\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/8-\u062a\u0627\u0628\u0639-p-\u0627\u0632-\u06a9\u0644\u0627\u0633-t.jpg\" alt=\"\" width=\"731\" height=\"300\" \/><\/p>\n<p>In general, this type of malware is operated in a way that, after changing the dns, once the victim enters a website like Google, a malware-infected application disguised as an update, or something similar (other legitimate applications) is installed on the smart phone, or it steals person&#8217;s user account information by displaying a phishing page when the victim logs into popular websites like facebook.com.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>How to deal with and clean the system?<\/strong><\/h2>\n<p>Padvish anti-malware detects this type of malware.<\/p>\n<p>Keep your smart phones up to date and make sure &#8220;Automatic update&#8221; feature is activated.<\/p>\n<p>Make sure you download\/ purchase your applications from trusted sources \/ app stores and do not download them from unknown sources (like Telegram channels, Instagram, or non-authenticated websites).<\/p>\n<p>Avoid clicking on suspicious links that you receive via SMS (clicking\u00a0on the\u00a0link\u00a0may have triggered malware to be downloaded).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Potential Damage: Medium Prevalence: Medium &nbsp; Malware name(s) Trojan.Android.Wroba.Roamingmantis (Padvish) HEUR:Trojan-Dropper.AndroidOS.Wroba.o (Kaspersky) ANDROID\/Drop.Wroba.monhn (Avira) &nbsp; What is a Trojan? Trojan is a type of malware that disguise itself as cleaned and legitimate software and behaves totally like a useful and functional software. But when executed, it causes a lot of damage to&hellip;<\/p>\n","protected":false},"author":21,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-1356","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1356","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1356"}],"version-history":[{"count":11,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1356\/revisions"}],"predecessor-version":[{"id":1549,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1356\/revisions\/1549"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1356"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1356"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}