Dissection Of Zertsecurity - Banking Trojan.
ID: 1ebaba28-b545-52f6-a25d-11ad55903451
STIX ID: report--1ebaba28-b545-52f6-a25d-11ad55903451
Feed Name: Zscaler Security Research Blog
Threat Score
Zertsecurity is a simple Android banking Trojan targeting German users via phishing: it prompts victims for account numbers and PINs, encrypts and stores the credentials in cfg.txt, exfiltrates the file to a hardcoded C&C server, and accepts SMS-based commands (identified by the string '&Sign28tepXXX'). The malware uses AES and Base64 encoding and requests SMS receive permissions to enable remote control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
