We first told you about it in 2021. BRATA had only just been discovered by Cleafy researchers when it arrived in Europe. Its operation was already grisly: through a phishing campaign, hackers managed to persuade their victims to download their malware, which they disguised as a bogus anti-spam application. Once installed, the user loses control of their smartphone and gains access to their bank information.
Already particularly dangerous, BRATA did not stop there. At the beginning of 2022, hackers are deploying an update that can reconfigure the smartphone to factory settings, while also making the malware completely undetectable. Today, Cleafy researchers have made some disturbing new discoveries. A lot of innovation has really gone into the process, starting with phishing pages that can now spy on the victim’s messages.
BRATA malware even more dangerous than before
This technique has two important advantages. First, it allows BRATA to retrieve the two-factor authentication codes required to sign in to certain accounts. Second, the malware automatically detects all usernames and passwords in the victim’s conversations, thereby putting their entire online life in danger.
Also, BRATA has noticeably changed its strategy. As Cleafy explains, the malware “Now focused on targeting a specific bank for a few months before moving on to another target”. Finally, it installs a backdoor on the victim’s smartphone to allow for other possible attacks in the future. Now more than ever, be very careful with what you install on your phone.
Source : open
Support our work ❤️
If you enjoyed this article, consider leaving a tip to help us keep publishing great content.



























