TeaBot is spilling like hot tea across Google Play Store, once again. Since its emergence in 2021, the malware has undergone various upgrades to infiltrate more targets and expand its attack surface.

What’s going on?

  • Cleafy discovered the trojan disguised as a QR code app on Google Play Store, which has already spread to more than 10,000 devices. 
  • This is not the first time that TeaBot has propagated via the Play Store. The operators followed the same trick in January and while all malicious apps were removed by Google, the bot found its way back. 
  • The apps are acting as droppers and are submitted without malicious code. Moreover, they request minimal permissions from users, making it challenging for Google’s reviewers to find them dubious.
  • The malicious apps, in addition, include promised functionality - leading to positive reviews on the Play Store. 

Modus operandi

  • TeaBot posed as an app, dubbed QR Code & Barcode - Scanner, which is a legit QR scanning app. 
  • However, upon installation, it asks users to update the app from an external source. The download source was traced back to two GitHub repositories.
  • Following this upgrade, the app changes its name to QR Code Scanner: Add-On. This new app requests permissions to Accessibility Services. 

New app functionality

  • Grab screenshots, view user screen, and capture login credentials, 2FA, and SMS content.
  • Auto-grant permissions in the background without any user knowledge. 
  • TeaBot is actively targeting users in the U.S., Russia, and China. 

The bottom line

This latest tactic adopted by TeaBot ensures that it freely passes the checks implemented by the Google Play Store. Since it can be confused with legitimate apps, common antivirus solutions cannot detect it either. The threat actors are, furthermore, working on robust obfuscation methods. Therefore, in order to reduce the possibility of becoming a victim of banking trojans, it is advised to keep the number of installed applications to a minimum.

Cyware Publisher

Publisher

Cyware