Advisory ID: NCC-CSIRT-2025-014
Summary:
A sophisticated and dangerous Android banking trojan, known as "Hook," is being actively distributed to target users of banking, financial, and cryptocurrency applications. Hook is designed to steal credentials and Personally Identifiable Information (PII) through overlay attacks and has evolved to include capabilities for full remote device takeover, data exfiltration, and ransomware-like features. The primary infection vector is social engineering, tricking users into installing malicious applications from unofficial sources.
Damage/Probability: High/Critical
Product(s):
Android Mobile Devices and Applications (Banking, Financial, and Cryptocurrency Apps)
Version(s):
All versions of Android OS (targeted via malicious apps)
Platform(s):
Android OS
Description:
The Hook trojan operates by masquerading as a legitimate application, such as a utility tool, system update, or a popular app. Once installed, it persistently requests the user to grant it powerful permissions, specifically targeting Android's Accessibility Services.
Upon receiving these permissions, Hook gains the ability to:
- Perform Overlay Attacks: When a user opens a targeted banking or financial app, Hook displays a fake, identical-looking login screen over the real app. The user unknowingly enters their credentials into this malicious window, which are then captured and sent to the attacker's server.
- Act as a Remote Access Tool (RAT): Attackers can establish a remote connection to the infected device, view the screen in real-time, simulate screen taps, log keystrokes, and navigate the device's user interface.
- Intercept Communications: The malware can read SMS messages, allowing it to bypass Two-Factor Authentication (2FA) codes sent via text.
- Exfiltrate Files: Hook can browse the device's file system and steal sensitive documents, photos, and other personal data.
Impacts:
A successful infection by the Hook trojan can lead to severe consequences, including:
- Direct Financial Loss: Unauthorized access to bank accounts, leading to theft of funds.
- Data Breach: Theft of sensitive personal information, including login credentials for multiple services, contacts, and private files.
- Identity Theft: The stolen information can be used to impersonate the victim and open fraudulent accounts.
- Complete Device Compromise: Attackers can gain full control over the device, using it for further malicious activities.
- Ransomware Attack: The trojan can lock the device's screen and demand a ransom payment for its release.
Solutions:
All Android users are strongly advised to adopt the following security measures to protect against this threat:
Immediate User Actions:
- Restrict App Sources: Only install applications from the official Google Play Store. Disable the "Install from unknown sources" option in your Android settings.
- Scrutinize Permissions: Be extremely cautious of any application requesting Accessibility Service permissions. These permissions grant extensive control over your device and should only be given to fully trusted applications from reputable developers.
- Enable Google Play Protect: Ensure this built-in security feature is active on your device.
- Update Regularly: Keep your Android operating system and all installed applications updated to the latest versions to ensure you have the most recent security patches.
- Practice Phishing Awareness: Do not click on suspicious links or download attachments from unknown senders in emails, SMS, or messaging apps.
- Use a Mobile Security Solution: Install a reputable antivirus or anti-malware application from a known security vendor.
If an Infection is Suspected:
- Immediately disconnect the device from all networks (Wi-Fi and Mobile Data).
- Boot the device into Safe Mode to prevent third-party apps from running and attempt to uninstall the malicious application.
- If the malicious app cannot be removed, a full factory reset is the most reliable method to ensure the malware is completely eradicated. Note that this will erase all data on the device.
- After securing your device, immediately change the passwords for your banking, email, and other critical online accounts from a separate, trusted device.
References:
- https://zimperium.com/blog/hook-version-3-the-banking-trojan-with-the-most-advanced-capabilities
-
https://blog.polyswarm.io/hook-android-banking-trojan-evolves
-
https://thehackernews.com/2025/08/hook-android-trojan-adds-ransomware.html
-
https://www.scworld.com/brief/more-sophisticated-hook-android-banking-trojan-emerges
Advisory ID: ngCERT-2025-080003
SUMMARY
ngCERT is aware of a persistent “AdLoad” malware infiltrating macOS through deceptive installers and bypassing Apple’s native security protections. Once installed, it hijacks browsers, injects unwanted advertisements, and collects user data while embedding itself deeply via launch agents, login items, and configuration profiles to maintain persistence. Detecting AdLoad can be challenging due to its stealthy nature and use of legitimate system mechanisms. Manual detection involves inspecting login items, system profiles, and startup agents, but these methods may miss advanced variants. Proactive monitoring, regular audits, and user education are crucial for mitigating risk and protecting system integrity. The malware exemplifies the increasing sophistication of macOS threats, making layered defense and timely detection critical to maintaining secure computing environments.
Probability: High
Damage: Critical
Platform(s): macOS (Intel + Apple Silicon)
DESCRIPTION
AdLoad is a sophisticated adware targeting macOS, utilising deceptive installers to infiltrate systems without detection. It exploits macOS’s native features to establish deep persistence, manipulating browser settings and injecting unsolicited advertisements. Unlike typical malware, AdLoad blends into legitimate system processes, complicating detection efforts. Indicators of infection include unexpected browser redirects, unfamiliar startup items, and subtle system slowdowns. Its stealth is enhanced by employing configuration profiles and launch agents, tools generally used for legitimate purposes. Traditional antivirus tools often struggle to identify AdLoad due to its use of signed components and legitimate macOS mechanisms.
CONSEQUENCES
Successful exploitation of Adload malware may lead to the following outcomes:
- Persistent and Intrusive Advertisements: AdLoad continuously injects unwanted ads into browsers and applications, disrupting normal workflows and degrading the overall user experience.
- Browser Hijacking and Redirects: The malware modifies browser settings to redirect users to suspicious or malicious websites.
- Unauthorized Data Collection: AdLoad covertly gathers browsing history, search queries, and other personal information without user consent.
- Difficult Removal and Persistence: Utilizing legitimate macOS mechanisms like launch agents and configuration profiles, AdLoad embeds itself deeply within the system.
- Degraded System Performance: Running background processes and injecting ads consume CPU, memory, and network bandwidth, leading to slower system responsiveness and reduced efficiency over time.
- Potential Vector for More Threats: By weakening system security and opening hidden backdoors, AdLoad can serve as a gateway for more dangerous malware, including ransomware or spyware.
SOLUTION/MITIGATION
To mitigate the risks associated with adload malware, ngCERT recommends the following actions:
- Use trusted anti-malware tools.
- Perform manual inspection and cleanup.
- Keep macOS and software updated.
- Limit software installation sources.
- Educate users on phishing and fake installers.
- Implement endpoint monitoring.
- Restrict administrative privileges.
- Maintain regular backups.
HYPERLINK
Advisory ID: ngCERT-2025-080002
SUMMARY
ngCERT is aware of an increase in Android.Vo1d malware infections within the Nigerian cyberspace. Android.vo1d, otherwise known as Void, is a recent Android Trojan campaign reported to have infected over 1.3 million Android TV boxes worldwide, including in Nigeria. The malware is identified as a sophisticated backdoor capable of secretly downloading and installing malicious applications on infected devices, particularly those running outdated Android operating systems. Android.vo1d poses a major risk to Android TV box users, with implications on system compromise and takeover, as well as data exfiltration, among other negative impacts. Consequently, ngCERT strongly advises individuals and organisations to take immediate steps to safeguard their systems and data from this emerging threat.
Probability: High
Damage: Critical
Platform(s): Android 7.1.2, Android 10.1, Android 12.1
DESCRIPTION
Android.Vo1d is a backdoor trojan that installs itself deep in the device’s system files and operates covertly by employing advanced techniques to evade detection while establishing persistence. It achieves this by infiltrating the system storage and modifying critical files like install-recovery.sh and daemonsu files. Thereafter, it creates news files, /system/bin/debuggerd, /system/bin/debuggerd_real, /system/xbin/vo1d,and /system/xbin/wd. Attackers cleverly disguises the malware by altering the file name “vold,” a system program, to “vo1d,” substituting the lowercase “l” with the number “1”. This trick allows the malware to evade detection while establishing a foothold in infected systems. Additionally, the backdoor’s components, Android.Vo1d.1, Android.Vo1d.3, and Android.Vo1d.5 work concurrently to ensure continued malicious activity. Particularly, Vo1d.1 manages activities and downloads executables files from the C&C server, Vo1d.3 installs and launches the encrypted Android.Vo1d.5 daemon, while monitoring directories and installing APK files, with Vo1d.5 providing additional functionality. Furthermore, TV boxes running older Android versions are particularly vulnerable, as they often lack critical security updates. Some of these devices include the R4 (Android 7.1.2) and KJ-SMART4KVIP (Android 10.1).
CONSEQUENCES
Falling prey to these attacks could potentially lead to:
- System compromise.
- Unauthorised access to sensitive data.
- Data exfiltration.
- Reputational damage.
- Service Disruption leading to potential Denial of Service (DoS).
SOLUTION/MITIGATION
ngCERT recommends the following:
- Regularly update of TV box firmware from official sources.
- Installation of antivirus software to detect potential infections.
- Avoid downloading apps or firmware from unofficial sources.
- Consider replacing TV boxes running on outdated Android versions with newer and more secure models.
HYPERLINK
- https://cybersecuritynews.com/android-tv-box-android-vo1d-malware/
- https://securityonline.info/massive-android-tv-box-infection-over-1-3-million-devices-compromised-by-android-vo1d/
- https://thehackernews.com/2024/09/beware-new-vo1d-malware-infects-13.html
- https://www.androidheadlines.com/2024/09/these-android-tv-boxes-are-infected-by-vo1d-malware.html
Advisory ID: ngCERT-2025-080001
SUMMARY
ngCERT has identified malware tagged android.badbox2. The malware, also known as BadBox 2.0, is a large-scale Android malware supply chain threat which involves the pre-infection of consumer devices. The malware is embedded into the system firmware before the device reaches consumers, making it resistant to removal. Low-cost Android devices using the Android Open Source Project (AOSP), such as Android tablets, connected TV (CTV) devices, digital photo frames, phones etc., are often targeted. This malware enables activities like remote code execution, account abuse, and ad fraud. Organisations and individuals are advised to stay vigilant and prioritise device hygiene to mitigate Android.BadBox2 risks.
Probability: High
Damage: Critical
Platform(s): Android TV Boxes, Smart Projectors, Android Tablets, Digital Signage Players and Uncertified Smartphones
DESCRIPTION
Android.BadBox2 is a sophisticated malware campaign that targets uncertified Android devices, primarily those using the AOSP. The infection begins at the supply chain level, with malicious code embedded directly into system files such as ‘libanl.so’, before the device even reaches the user. In other cases, the malware spreads through “evil twin” apps, counterfeit versions of legitimate applications that are sideloaded from third-party sources. Once installed, the malware connects to remote Command and Control (C2) servers, downloads additional payloads, and enables remote access via a component called BB2DOOR. This allows attackers to control the device, update malware, or install new modules silently. Once active, the malware enlists the device into a global botnet used for fraudulent activity. Infected devices are transformed into residential proxy nodes, allowing attackers to route malicious traffic through victims’ home networks. The malware also engages in ad and click fraud by launching hidden browser sessions that load ads in the background, consuming data and battery without the user’s knowledge. With deep system integration, Android.BadBox2 can disable security features, avoid detection, and persist even through factory resets, thereby posing a serious threat to user privacy, network integrity, and global digital infrastructure.
CONSEQUENCES
Falling prey to these attacks could potentially lead to:
- System compromise.
- Unauthorised access to sensitive data.
- Data exfiltration.
- Reputational damage.
- Service Disruption leading to potential Denial of Service (DoS).
- Legal Implications.
SOLUTION/MITIGATION
The following recommendations should be observed to mitigate risks:
- Monitor network activity across all connected devices.
- Update software, firmware, and operating systems regularly.
- Avoid using unofficial app stores or sideloaded software.
- Be wary of too-good-to-be-true streaming solutions.
HYPERLINK
Advisory ID: NCC-CSIRT-2025-013
Summary:
Cybersecurity researchers have uncovered a large-scale phishing-as-a-service (PhaaS) infrastructure on Google Cloud and Cloudflare, which has been operational for years. This infrastructure utilizes fake websites that mimic real company login pages to steal passwords and bypass security codes. The attackers stay hidden by using expired domains and tricks that fool Google into seeing harmless content.
Damage/Probability: High/Critical
Product(s):
- Google Cloud Platform (GCP)
- Cloudflare Services
- Expired or Abandoned Domains
Version(s):
- Google Cloud Platform (GCP): Not version-specific (cloud services, not software releases).
- Cloudflare Services: Not version-specific (service-level abuse).
- Expired or Abandoned Domains: Any domains previously registered but left to expire.
Platform(s):
Google Cloud, Cloudflare, Re-registered / Expired Domains, and Open Redirect Services (e.g., Google Accelerated Mobile Pages (AMP), Software-as-a-Service (SaaS) platforms).
Description:
According to the cybersecurity experts, the attackers create fake websites that look exactly like the real login pages of well-known companies (including big defence, finance, and tech firms). Their goal is to trick people into entering their usernames, passwords, and even security codes. Once stolen, this information can be used to hack accounts, steal money, spread malware, or commit fraud.
The group has built an “empire” of fake sites, with almost 50,000 fake hosts across many servers. To stay hidden, they use clever tricks:
- They buy expired websites that already have a good reputation in Google search.
- They make sure Google’s systems see a harmless version of the site, while real users see the fake login page.
- They even load some images or files directly from the real company’s website, so the fake page looks even more convincing.
Because of these tactics, the operation managed to run for years without being shut down.
Impacts:
- Credential compromise & account takeover (ATO) including Multi-Factor-Authentication (MFA) bypass where Adversary-in-the-Middle (AiTM) kits are used.
- Brand/reputation damage and potential regulatory exposure where cloned sites load legitimate brand assets.
- Downstream malware delivery (e.g., RATs via Cloudflare-hosted chains in adjacent campaigns). .
Solutions:
What Users Should Do:
- Do not rely on search results for logins. Always type the web address yourself (e.g., www.yourbank.com) or use bookmarks you created earlier.
- Look carefully at website addresses. Fake sites often use unusual spellings or extra words.
- Use stronger sign-in methods. Where possible, use security keys or passkeys (FIDO2/WebAuthn) instead of just passwords and codes. These are very hard for attackers to steal.
- Be alert for suspicious redirects. If a link takes you through multiple pages before reaching a login, it could be a trap.
- Report suspicious sites. If you see a fake site pretending to be your organization, report it immediately to IT/security teams.
What Organizations Should Do:
- Protect your domains: Renew important website names on time so criminals can’t take them over.
- Monitor your brand: Regularly check if fake versions of your website exist and request takedowns quickly.
- Strengthen staff login security: Use multi-factor authentication, preferably phishing-resistant methods.
- Train employees: Remind staff to never log in through links in emails or search results.
References:
- https://www.darkreading.com/cloud-security/phishing-empire-undetected-google-cloudflare
-
https://malwaretips.com/threads/phishing-empire-runs-undetected-on-google-cloudflare.137414/
-
https://reporter.deepspecter.com/the-cloak-and-the-dagger-how-google-and-cloudflare-missed-a-global-phishing-empire-ed7176ebf82f
- Dangerous Linux Malware Hides in RAR File Names to Evade Antivirus Detection
- New “PS1Bot” Malware Campaign Uses Malvertising to Deliver Multi-Stage, In-Memory Attacks
- WinRAR Zero-Day Vulnerability exploited to Plant RomCom Backdoors via Archive Extraction
- Bluetooth Flaws May Turn Audio Devices into Spy Tools