Asacub Trojan Moves From Spyware to Banking Malware | eWeek

Asacub Trojan Moves From Spyware to Mobile Banking Malware

Asacub mobile banking Trojan
Jan 21, 2016
2 minute read
eWeek Inhalte und Produktempfehlungen sind redaktionell unabhängig. Wir können Geld verdienen, wenn Sie auf Links zu unseren Partnern klicken. Mehr erfahren

Security firm Kaspersky Lab is warning of an evolving threat from a mobile banking Trojan, dubbed Asacub, which appears to be using infrastructure elements that the CoreBot Windows spyware Trojan employs.

Asacub emerged in June 2015 and was initially acting as an information-stealing Trojan that pilfered user contact lists and browser history. Kaspersky Lab’s analysis shows that in late 2015 Asacub evolved to become a full-featured mobile banking Trojan that steals money from victims. The mobile banking evolution of Asacub includes features that enable the Trojan to show a phishing page for a banking application.

“In total, we saw attempts to infect more than 16,000 of our users, according to data from our Kaspersky Security Network,” Roman Unuchek, senior malware analyst at Kaspersky Lab, told eWEEK. “It is hard to say how many users were infected because many consumers still do not have any form of antivirus protection.”

For Asacub, getting onto user devices usually involves an effort to deceive the user into somehow installing a malicious application.

“They use SMS [Short Message Service] spam and phishing to force the user to install this Trojan,” Unuchek said. “In most cases, it looks like an app to view images or MMS [Multimedia Messaging Service].”

Asacub targets all Android users, even those with fully patched and up-to-date devices. Although Asacub does not exploit any vulnerabilities in Android, the Trojan simply abuses the permissions it gets when the user is deceived into installing it, Unuchek said.

“Standard permissions are enough,” Unuchek said. “There is no need for any extraordinary permission to overlap another app with a phishing window.”

Kaspersky Lab also found that Asacub was using the same command-and-control backend infrastructure that the Windows CoreBot spyware tool employs. This is not the first time Unuchek has seen Windows malware operations use the same command-and-control infrastructure for Android malware, but it is not a common situation.

Advertisement

“Asacub could be Corebot’s mobile version,” Unuchek wrote in a blog post. “However, it is more likely that the same malicious actor purchased both Trojans and has been using them simultaneously.”

Unuchek noted that Kaspersky Lab will share the details of what it discovered during the Asacub investigation with law enforcement agencies and other organizations interested in fighting cyber-threats.

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Eigentum von TechnologyAdvice. © 2026 TechnologyAdvice. Alle Rechte vorbehalten

Werbetreibenden-Offenlegung: Einige der auf dieser Website erscheinenden Produkte stammen von Unternehmen, von denen TechnologyAdvice eine Vergütung erhält. Diese Vergütung kann beeinflussen, wie und wo Produkte auf dieser Website erscheinen, einschließlich beispielsweise der Reihenfolge, in der sie erscheinen. TechnologyAdvice schließt nicht alle Unternehmen oder alle auf dem Marktplatz verfügbaren Produkttypen ein.