Analysts Detect New Banking Malware

Leo Daniels • July 23, 2020

This is a subtitle for your new post

A new strain of banking malware dubbed BlackRock has been detected by researchers at Threat Fabric. 

An investigation into its origins has revealed BlackRock to be derived from the Xerxes banking malware. Xerxes was in turn spawned out of the LokiBot Android banking Trojan, first detected around four years ago.

The source code of the Xerxes malware was made public by its author around May 2019, making it possible for any threat actor to get their hands on it. Despite the code’s availability, researchers found that the only Android banking Trojan based on Xerxes’ source code that is currently operating appears to be BlackRock.

This malevolent malware steals credentials not only from banking apps but also from other apps designed to facilitate communication, shopping and business. In total, the team found 337 Android apps were impacted, including dating, social networking and cryptocurrency apps. 

By throwing their nefarious campaign net so wide, researchers believe the malware’s creators are attempting to exploit the increase in online socializing brought about by the outbreak of COVID-19.

“Technical aspects aside, one of the interesting differentiators of BlackRock is its target list; it contains an important number of social, networking, communication and dating applications,” noted researchers. 

“So far, many of those applications haven’t been observed in target lists for other existing banking Trojans. It therefore seems that the actors behind BlackRock are trying to abuse the growth in online socializing that increased rapidly in the last months due to the pandemic situation.”

BlackRock was first spotted back in May 2020. When the malware is launched on a device for the first time, its icon is hidden from the app drawer, making it invisible to the end user. The malware then asks the victim for the Accessibility Service privileges, often posing as a Google update. 

Once the user grants the request, BlackRock starts granting itself the additional permissions required for the bot to fully function without having to interact any further with the victim. When done, the bot is functional and ready to receive commands from the C2 server and perform the overlay attacks.

“Unfortunately, this malware is particularly sophisticated and can camouflage itself as a genuine app to do some damaging spy work in the background,” commented ESET cybersecurity specialist Jake Moore.

“It is vital that users know what apps they are downloading, or they may risk unknowingly downloading something illicit.”

 

We’re 1-fix, we can help you secure your business

At 1-fix, we take a realistic approach to technology – ensuring our client’s systems are best protected.

If you have any concerns, questions or simply want to explore how to better secure your business, please do get in touch with the team for a FREE demonstration, consultation to explore how exposed your business might be and identify actions to take.

Join Our Mailing List

All sign-ups are handled inline with our privacy policy and can unsubscribe at any time.

IT Support Services
Cybersecurity Deep-Dive
IT Cloud Migration Service

Recent Blogs

a man and a women sat smiling at each other on a desk with a laptop and screen in front of them
By Craig Atkins September 25, 2025
Discover how friendly IT support boosts efficiency, security, and growth for modern businesses.
By Jess Dugdale August 15, 2025
Join our free 30-min webinar on 3 Sept to learn what Windows 10 end-of-life means and how to upgrade for free—plus win a Hotel Chocolat bundle!
AI image of colleagues working on laptops with cloud icons in the background
By Craig Atkins July 24, 2025
Planning to move to the cloud? Discover what to expect, key benefits, and how 1-Fix IT support ensures a smooth, secure migration for your business.
AI image of workers in an open office on computers.
By Grant Taylor-Davis July 21, 2025
Cut costs and reduce your carbon footprint with cloud migration. Discover how 1-Fix IT support helps businesses save and go green with managed IT services.
AI image of colleagues on laptops that are connected to the cloud
By Lee DS July 15, 2025
Discover why summer is the perfect time to move to the cloud. Learn how cloud migration boosts flexibility, security & cost-efficiency with 1-Fix IT support.
AI image of people sat round a desk discussing cybersecurity in business.
By Craig Atkins July 7, 2025
Protect your business with expert IT support. Learn why cybersecurity is vital for reputation, compliance, and long-term success.
Show More