New Octo2 Malware Targets Europe, Disguises as Legitimate Apps

25 Sep 2024

A new variant of the Octo Android malware, dubbed “Octo2,” has emerged in Europe, masquerading as legitimate applications such as NordVPN, Google Chrome, and a program named Europe Enterprise. This latest iteration, thoroughly examined by ThreatFabric, showcases enhanced operational stability and sophisticated mechanisms designed to evade analysis and detection. Notably, it employs a domain generation algorithm (DGA) system, which bolsters its command and control (C2) communications, ensuring resilience against disruptions.

Brief History and Evolution

The Octo malware is rooted in the Android banking trojan lineage, evolving from ExoCompact, which was active from 2019 to 2021. This earlier variant was itself derived from the ExoBot trojan, first introduced in 2016, whose source code was leaked in mid-2018. ThreatFabric initially uncovered Octo in April 2022, embedded within counterfeit cleaner applications on Google Play. Their findings revealed the malware’s extensive on-device fraud capabilities, granting operators significant access to victims’ sensitive information.

Octo v1 was equipped with a range of functionalities, including:

  • Keylogging
  • On-device navigation
  • Interception of SMS and push notifications
  • Device screen locking
  • Sound muting
  • Arbitrary app launches
  • Utilization of infected devices for SMS distribution

Earlier this year, the original Octo was leaked, leading to the emergence of multiple forks of the malware. This development likely impacted the sales of its original creator, known as ‘Architect.’ In response, Architect introduced Octo2, presumably to reinvigorate interest among cybercriminals. The creator even offered a special discount for existing customers of Octo v1.

Octo2 Operations in Europe

Current campaigns utilizing Octo2 are primarily targeting Italy, Poland, Moldova, and Hungary. However, given the malware’s previous reach through the Malware-as-a-Service (MaaS) platform, which has facilitated attacks globally—including in the U.S., Canada, Australia, and the Middle East—it’s anticipated that Octo2 will soon extend its operations to other regions.

In these European campaigns, threat actors are leveraging counterfeit NordVPN and Google Chrome applications, alongside the Europe Enterprise app, likely as bait for targeted attacks. Octo2 employs the Zombider service to embed the malicious payload into these APKs, successfully circumventing security measures introduced in Android 13 and later versions.

More Stable, More Evasive, More Capable

Octo2 represents a refined upgrade to its predecessor, enhancing its capabilities incrementally rather than through radical overhauls. A notable addition is the introduction of a low-quality setting within the remote access tool (RAT) module, aptly named “SHIT_QUALITY.” This feature minimizes data transmissions, ensuring more reliable connectivity even under poor internet conditions.

Furthermore, Octo2 employs native code to decrypt its payload and complicates analysis by dynamically loading additional libraries during execution, significantly bolstering its evasion tactics. The introduction of a DGA-based C2 domain system allows operators to swiftly update and switch to new C2 servers, rendering blocklists ineffective and enhancing resilience against server takedown efforts.

ThreatFabric also highlights that Octo2 now receives a curated list of applications to intercept, enabling operators to fine-tune their targeting strategies. Currently, Octo2 has not been detected on Google Play, indicating that its operators are relying on alternative distribution channels to propagate the malware.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
5735808
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1033196
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
441314
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
373796
downloads

News and reviews for Mobile Android

Latest Insights on Android Deals Highlight Game Opportunities

Discover Thursday's top Android game and app deals with notable discounts on Google Play, bringing a range of engaging options for users. Explore a wealth of offerings like Smart DNS Changer Pro, Chronomon, Wreckfest, and more alongside insights from senior deal expert, Justin.

Read more

Silksong Reimagines Windows Gaming on Android Devices

Silksong leads the charge in bringing Windows gaming to Android. Following the impact of the Steam Deck, this move signals a growing trend in mobile gaming innovation, providing gamers a seamless handheld experience.

Read more

PlayStation Family App Launch Enhances Parental Controls

Sony introduces the PlayStation Family app for mobile devices, allowing easy control over PS4 and PS5 parental settings. This app provides parents with tools to set playtime, spending, and content restrictions, ensuring a safer gaming experience.

Read more

PlayStation Family App Brings Parental Controls to Mobile

Sony's PlayStation Family app offers parents remote control over children's PlayStation activity, including playtime and spending limits, directly from mobile devices.

Read more

Health Connect May Evolve Into Fitness Tracking Platform

Health Connect may add native step tracking features, indicating a shift from data hub to fitness tracker by using phone sensors for direct data collection.

Read more

Identity Check Update Enhances Pixel Watch Integration

Android 16 update adds compatibility with Pixel Watch for Identity Check, allowing PIN, password, or pattern access without biometric sign-in. This feature is supported on Pixel Watch 3 and 4.

Read more

PlayStation Family App Empowers Parental Control on Consoles

Sony's PlayStation Family app for iOS and Android enhances parental control over children's gaming experiences on PS5 and PS4.

Read more

BGMI 4.0 Update Brings New Features and Ghost Companions

Krafton introduces BGMI 4.0 update with Spooky Soiree features, ghost companions, and innovative game modes for Android. Experience enhanced gameplay with new strategic abilities.

Read more

Microsoft to Retire Outlook Lite Android App October 2025

Microsoft pulls Outlook Lite from Play Store in October 2025. Users are encouraged to switch to Outlook Mobile app for enhanced features and support.

Read more

Sideloading Faces New Restrictions Under Google's Policy Shift

Google's new Android policy limits sideloding. Apps must be signed by verified developers, removing flexibility. Critics worry about increased control and privacy concerns.

Read more