New Octo2 Malware Targets European Banking Customers via Trusted Apps

25 Sep 2024

Emerging Threats in Cybersecurity

The cybersecurity landscape is witnessing a notable evolution with the emergence of a new version of the Octo Android malware, which has recently begun its spread across Europe. This sophisticated malware masquerades as well-known applications, including NordVPN and Google Chrome, thereby leveraging the trust users place in these brands. Researchers from ThreatFabric have identified this latest iteration, dubbed Octo2, which also targets a region-specific application named Europe Enterprise.

Octo2 has been designed with advanced anti-detection mechanisms and a domain generation algorithm that facilitates command-and-control communication. The malware’s enhanced stability and persistence make it particularly concerning for infected devices, as it becomes increasingly difficult to detect and remove.

Originating from the ExobotCompact malware family, which first appeared in 2016 as a banking Trojan, Octo2 has evolved into one of the most prevalent Android malware strains, primarily targeting banking customers worldwide. The initial sightings of Octo2 were reported in countries such as Italy, Poland, Hungary, and Moldova, where its ability to impersonate trusted applications has significantly contributed to its spread among unsuspecting users.

Key Advancements in Octo2

One of the key advancements in Octo2 is its focus on improving remote access functionality, a critical aspect for executing device takeover attacks. To optimize data transmission and enhance connection stability, the malware incorporates a setting humorously referred to as SHIT_QUALITY. This feature reduces the quality of images sent from the infected device to the command-and-control server, ensuring reliable communication even in subpar network conditions.

Moreover, Octo2 has fortified its anti-analysis and anti-detection capabilities, characteristics that have long defined the ExobotCompact lineage. The malware employs dynamic loading of its malicious code, which is decrypted through multiple layers of protection, further complicating detection efforts.

Domain Generation Algorithm

A particularly noteworthy innovation within Octo2 is its use of a domain generation algorithm for command-and-control communication. This allows the malware to create new domain names dynamically, ensuring that attackers retain control over infected devices even if security teams succeed in dismantling known command-and-control servers. However, this algorithm does have a limitation; once researchers decipher its workings, antivirus vendors can anticipate and block future domain names, potentially mitigating the threat.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6743343
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1430182
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
577697
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
463521
downloads

News and reviews for Mobile Android

Android 16 Upgrade Enhances Pixel Devices with New Features

Android 16 QPR2 update brings new UI, AI features, and security to Pixel devices, enhancing both functionality and safety.

Read more

Google Drops 'Call Home' from Home App, Affecting Nest Users

Google removed 'Call Home' from its Home app, impacting Nest device interactions. Users express frustration; alternatives are less seamless.

Read more

Discounts Live for Popular Android Apps and Games

Notable Android app and game deals this week: Incredibox, Railways Simulator, and more see price drops amid Cyber Monday extensions.

Read more

MLB Mobile Debuts in the Philippines: What to Expect

Sony's MLB Mobile launched in the Philippines as a standalone mobile game. Available on iOS and Android, it offers solo and multiplayer modes.

Read more

Red Dead Redemption Launches on Android and iOS via Netflix

Rockstar Games releases Red Dead Redemption on mobile via Netflix. Available for Android and iOS as of 2025-12-03 with the Undead Nightmare DLC.

Read more

Android Introduces Screen Sharing Scam Alerts in the US

Android launches a new scam-protection pilot for screen sharing on banking apps in the US to curb social-engineering fraud.

Read more

DATA2073 Enhances Android App with Faster Gameplay and Web3 Tools

DATA2073's Android update boosts gameplay speed and Web3 integration, elevating mobile engagement and security.

Read more

Red Dead Redemption Expands to Mobile Platforms

Rockstar Games' Red Dead now available on Android, iOS; Netflix users access it free.

Read more

Red Dead Launches on Mobile via Netflix Games

Red Dead Redemption now on Android and iOS via Netflix Games, featuring new visuals and controls.

Read more

Red Dead Redemption Now on Mobile via Netflix Games

Red Dead Redemption launches on Android and iOS via Netflix Games, joining current-gen consoles with enhanced features.

Read more