Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Bitcoin may have bottomed at $60,000, says Coinbase (COIN) CEO

June 15, 2026

The CLARITY Act has a two-month window. Here is the map

June 15, 2026

LayerZero rallies 14% ahead of $23mln token unlock – Can ZRO break $1.15?

June 15, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»New Android Banking Trojan ‘Nexus’ Promoted As MaaS
New Android Banking Trojan 'Nexus' Promoted As MaaS
Security and Privacy

New Android Banking Trojan ‘Nexus’ Promoted As MaaS

May 25, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A new Android banking Trojan has been discovered in several malicious campaigns worldwide. Dubbed ‘Nexus’ by Cleafy security researchers, the tool is promoted as part of a Malware-as-a-Service (MaaS) subscription and provides features to perform account takeover (ATO) attacks.

“In January 2023, a new Android banking Trojan appeared on multiple hacking forums under the name of Nexus,” wrote the company in an advisory published on Tuesday. “However, [we] traced the first Nexus infections way before the public announcement in June 2022.”

Analysing Nexus samples last year, Cleafy noticed code similarities between the malware and SOVA, an Android banking trojan discovered in mid-2021. At the time, the team believed Nexus to be an updated version of SOVA.

“Despite the new MaaS program launched under the name Nexus, the authors may have reused some parts of SOVA internals to write new features (and rewrite some of the existing ones),” explained Cleafy.

“Recently, the SOVA author, who operates under the alias ‘sovenok,’ started sharing some insights on Nexus and its relationship with SOVA, calling out an affiliate who previously rented SOVA for stealing the entire source code of the project.”

Regarding features facilitating ATO operations, Nexus offers overlay attacks and keylogging activities designed to steal victims’ credentials. It can also steal SMS messages (to obtain two-factor authentication codes) and information from cryptocurrency wallets.

Read more on banking trojans here: Researchers Discover Nearly 200,000 New Mobile Banking Trojan Installers

“Nexus is also equipped with a mechanism for autonomous updating,” Cleafy wrote. “A dedicated function asynchronously checks against its C2 server for updates when the malware is running.”

See also  Ex-Coinbase Executive Slapped With Two-Year Prison Sentence on Crypto Asset Insider Trading Charges

The malware also includes a module capable of encryption, possibly ransomware.

“This module seems to be under development due to the presence of debugging strings and the lack of usage references,” the company clarified.

More generally, Cleafy said that the absence of a virtual network computing (VNC) module (that would allow for remote access) currently limits the action range and capabilities of Nexus.

“However, according to the infection rate retrieved from multiple C2 panels, Nexus is a real threat that is capable of infecting hundreds of devices around the world,” the security team warned. “Because of that, we cannot exclude that it will be ready to take the stage in the next few months.”

Source link

Android Banking MaaS Nexus Promoted Trojan
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

What The FIFA World Cup 2026 Means For Fraud

June 12, 2026

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

June 10, 2026

North Korean Hackers Use Fake Coding Tasks to Steal Crypto

June 8, 2026

Federal Reserve Vice Chair Bowman testifies on banking supervision, signals pro-crypto regulatory shift

June 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

SEC pushes back against Richard Heart’s bid to dismiss $1 billion fraud case

August 24, 2024

Bitcoin’s Difficulty Soars Past 100 Trillion—How Are Miners Adapting?

November 6, 2024

Bitcoin Spot ETF Will Bring $70 Billion In New Money

November 25, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bitcoin may have bottomed at $60,000, says Coinbase (COIN) CEO

June 15, 2026

The CLARITY Act has a two-month window. Here is the map

June 15, 2026

LayerZero rallies 14% ahead of $23mln token unlock – Can ZRO break $1.15?

June 15, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$66,457.003.37%
  • ethereumEthereum(ETH)$1,812.508.80%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$625.832.42%
  • rippleXRP(XRP)$1.249.35%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$73.658.80%
  • tronTRON(TRX)$0.3202781.12%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.010.00%
  • HyperliquidHyperliquid(HYPE)$67.169.93%