Listen to this episode

Unmasking the Xenomorph: An In-Depth Discussion on Android Security and Cybersecurity

0:0048:32

Recorded September 2023. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig Petronella and Blake Rea discuss the Xenomorph banking Trojan, a malware strain targeting Android users that, at the time of recording, reportedly affects more than 35 financial institutions and some crypto wallets. Craig explains it seeks credentials, balance information, MFA tokens and fund transfers, while Blake notes it was reported to affect only Android 13, the previous operating system generation.

The hosts argue nothing is foolproof and advocate layered defenses: patched devices, a clean dedicated device for banking, password managers instead of typed URLs, multi-factor authentication, keystroke encryption, XDR tools, and caution over apps and Chrome extensions. They warn malicious apps exist on both Google Play and Apple's App Store, urging listeners to vet developers and restrict permissions. Blake recounts the Caesars MGM breach, where young attackers allegedly persuaded a help desk to reset an executive's credentials, and the pair discuss SIM swap attacks. Craig also raises reported security flaws in Hyundai and Kia key fobs, urging consumers to pressure vendors. He adds that at the time of recording FDIC insurance covers deposits up to $250,000, but stresses listeners still need their own protections.

Worth remembering

Key takeaways

  1. Craig recommends doing banking and other sensitive tasks on a secure, patched device with few apps, ideally a desktop, rather than a phone loaded with unknown apps.
    “try to use a more secure device that doesn't have much on it to do these things. Use a desktop.”
  2. Blake advises updating devices immediately and checking your phone for updates at least every week.
    “I always recommend people just update immediately. Check your phone every week at least for updates”
  3. Blake urges listeners to research the developer listed on every app, searching the name with terms like security or malware, before downloading.
    “be very weary of what apps you download, right, and who those developers are.”
  4. Blake suggests turning off camera, microphone or location permissions for apps you keep, and removing any app you have doubts about.
    “go in and limit what data and what controls it has over your phone.”
  5. Craig advises saving your bank's web address in a password manager instead of typing it, because mistyped domains are what attackers register.
    “don't type it in because you can fat finger it”
  6. Reacting to the MGM help desk story, Craig argues staff should verify identity, such as calling the executive back, before resetting anything.
    “never assume that this person on the other end of the phone is who they say they are. Verify it.”
  7. Craig recommends a PIN with your mobile carrier and avoiding text message one-time pins where possible to reduce SIM swap attack risk.
    “everyone listening should have a pin number with their mobile carrier to prevent SIM swap attacks”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Do you know how to protect your device from the Xenomorph Banking Trojan? Join us as we dive into the murky waters of Android security threats with our enlightening guest, Blake Rea. We unmask the frightening reality of this new Trojan, aimed solely at Android users. With a chilling focus on over 35 financial institutions and some crypto wallets, the need to understand and shield ourselves from this threat is apparent. As we unravel the differences between Android and Apple devices' security, we investigate a compelling conversation around trust and privacy, scrutinizing the potential for hardware chips that spy on us.

With the advent of the Xenomorph Banking Trojan looming, we guide you through the labyrinth of secure banking and device protection. How safe is it to download apps from the Google Play Store? Can a password manager protect you from threats? We answer these questions and more, offering pearls of wisdom on everything from encrypted drives and strong passwords to limiting app permissions. We also dissect the critical role of reading the Terms & Conditions of software applications - an often neglected, yet vital protective measure.

Switching gears, we delve into the intriguing world of social engineering and its dramatic impact on businesses. We unravel how trust is manipulated and the crucial need for verifying information in online banking. We share indispensable tips on SIM swap attacks and much more!

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.