Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Forget max pain. Bitcoin is well below the $72,000 magnet going into $10 billion options expiry

June 25, 2026

Brazil blocks crypto campaign donations before 2026 vote

June 25, 2026

Sahara AI surges: Can its price recovery survive a 1.03B token unlock?

June 25, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Android Banking Trojan SOVA Comes Back With New Features, Including Ransomware
Android Banking Trojan SOVA Comes Back With New Features, Including Ransomware
Security and Privacy

Android Banking Trojan SOVA Comes Back With New Features, Including Ransomware

June 15, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

The Android banking Trojan SOVA has been spotted in the wild again and appears to have new features.

The news comes from Cleafy’s security researchers, who shared the findings in an advisory on Thursday.

The document explains how SOVA was first spotted in September 2021, when its developers posted a roadmap of future updates on the dark web saying the malware was entering the market, despite still being under testing.

In the following months, Cleafy spotted various versions of SOVA, some of which implemented certain features mentioned in the malware’s 2021 development roadmap.

These included two-factor authentication (2FA) interception, cookie stealing and injections for new targets and countries (e.g. multiple Philippine banks).

Then, in July 2022, Cleafy spotted a new version of SOVA (v4), which the security firm is now detailing in its latest advisory.

SOVA v4 features new capabilities and is reportedly targeting more than 200 mobile applications (against the original 90 in 2021), including banking apps and crypto exchanges/wallets such as Binance.

“The most interesting part is related to the [Virtual Network Computing] capability,” Cleafy wrote. “This feature has been in the SOVA roadmap since September 2021 and that is one strong evidence that threat actors are constantly updating the malware with new features and capabilities.”

Additionally, the malware’s latest version can also obtain screenshots from the infected devices, record and perform gestures and manage multiple commands.

In SOVA v4, the cookie stealer mechanism was further refactored and improved to specify a a comprehensive list of targeted Google services, alongside a list of other applications. Further, the updated malware can now protect itself by intercepting actions aimed at uninstalling its app.

See also  ‘Trusted’ marketplace sold fake Trezor wallets stealing crypto — Kaspersky

In the same advisory, Cleafy also claimed to have spotted some instance of yet another variant of SOVA. The v5 of the malware shows a further refactoring of the code, the addition of new features and some small changes in the communications between the malware and the command-and-control (C2) server.

More specifically, SOVA v5 lacks the VNC module, but it instead features ransomware capabilities.

“The ransomware feature is quite interesting as it’s still not a common one in the Android banking trojans landscape,” Cleafy wrote.

“It strongly leverages on the opportunity arises in recent years, as mobile devices became for most people the central storage for personal and business data.”

Source link

Android Banking Features including Ransomware SOVA Trojan
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

The banking lobby is wrong about stablecoins and community banks

June 24, 2026

US Treasury’s $10B scam warning shows why crypto is racing to police itself

June 24, 2026

Why the banking industry is fighting a crypto bill

June 23, 2026

Loaded Lions’ Mane City Mobile Heads to iOS and Android as Sign-Ups Begin

June 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Cango Mines 602.6 BTC in October, Total Holdings Surpass 6,400 Bitcoin

November 4, 2025

Landmark crypto legislation defines SEC, CFTC jurisdiction on digital assets, commodities

July 27, 2023

The Growing Differences Between Competitive and Casual Gaming Audiences

April 21, 2026

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Forget max pain. Bitcoin is well below the $72,000 magnet going into $10 billion options expiry

June 25, 2026

Brazil blocks crypto campaign donations before 2026 vote

June 25, 2026

Sahara AI surges: Can its price recovery survive a 1.03B token unlock?

June 25, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$61,645.00-1.56%
  • ethereumEthereum(ETH)$1,645.48-1.18%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$567.95-1.47%
  • usd-coinUSDC(USDC)$1.000.01%
  • rippleXRP(XRP)$1.08-1.64%
  • solanaSolana(SOL)$68.81-0.61%
  • tronTRON(TRX)$0.328846-0.54%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.65%
  • HyperliquidHyperliquid(HYPE)$63.561.89%