What is SOVA Virus?

 By Dr.R.Prabusankar, Professor


Several Indian banks, including HDFC Bank and IDBI Bank, have warned account holders not to download mobile applications from sources other than official app stores. They issued the alert after consultation with India's computer emergency response team or his CERT-In. According to Cert-in's recommendations for India, "SOVA previously focused on countries such as the United States, Russia, and Spain, but will add several other countries, including India, to its target list in July 2022. SOVA, a new version of the Trojan virus reportedly targeted over 200 mobile banking and encryption apps to steal login credentials and cookies. You can keep the information for ransom.

What is SOVA?

SOVA is an Android banking Trojan that targets banking apps to steal personal information and add a layer of deception to many apps. These layers help malware mimic payment apps. This malware was first spotted for sale on the underground market in September 2021.

What can SOVA do?

• Collect keystrokes

• Steal cookies

• Intercept multi-factor authentication (MFA) tokens

• Take screenshots and record videos from webcams

• Android Accessibility Services to perform gestures such as screen clicks, swipes

• copy/paste

• add fake overlays to many apps

• mimic over 200 banking and payment applications.

How does SOVA work?

Malware is spread by smishing. Smishing is the process of sending people deceptive SMS asking them to share information such as passwords. When an app is downloaded to the phone, the malware sends a list of all downloaded apps to a server controlled by the attacker. The server sends the list of targeted apps back to the malware and saves important information in an XML file. Malware and the server then manage the app.

The app cannot be uninstalled

 After the latest update, when users try to uninstall the compromised app, they are unable to do so. A message "This app is protected" will appear on the screen.

How can users protect themselves?

Download the mobile apps only through official app stores. Also, check the "Additional Information" section while downloading the apps and review the app details, number of downloads, and user reviews. Another method recommended by CERT-In is to download the latest updates for apps and operating software provided by the device vendor. Also, download and enable antivirus software. Do not go to untrusted websites or follow untrusted links. Be careful when clicking on links in spam or SMS. If you experience any unusual activity on your bank account, please report it to the relevant bank immediately.

 Source: Business Standard, Times of India

Comments

Popular posts from this blog

The Glass Cliff Phenomenon

The Mind

Imposter Syndrome: The Paradox of Achievement