27. January 2022

This article has been indexed from

CySecurity News – Latest Information Security and Hacking Incidents

The BRATA Android malware has been updated to include additional functions such as GPS tracking and the ability to execute a factory reset on the device. 

The Android RAT BRATA (the term originates from ‘Brazilian RAT Android’) was founded in 2019 by Kaspersky security professionals and was used to eavesdrop on Brazilian users. In January 2019, the BRATA RAT was discovered circulating over WhatsApp and SMS communications. 

The RAT was distributed both through Google’s official Play Store and through alternative Android app marketplaces. The majority of the infected apps masquerade as an update to the popular instant messaging service WhatsApp, claiming to fix the CVE-2019-3568 vulnerability in the app. The malware will begin keylogging after it has infected the victim’s device, adding real-time streaming features to it. 

To connect with other apps on the victim’s device, the malware makes use of the Android Accessibility Service function. Many instructions are supported by BRATA, including unlocking the victims’ devices, gathering device information, shutting off the device’s screen to run tasks in the background, executing any specific application, uninstalling itself, and removing any infection traces. 

Researchers from security firm Cleafy discovered a new variation affecting Android banking users in Europe in December 2021, with the goal of stealing their passwords. The same researchers have now discovered a

[…]

Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: