Characterizing Malware-as-a-Service-Oriented Android Fraud Campaigns Targeting Brazil
Resumo
Android fraud campaigns increasingly exhibit Malware-as-a-Service (MaaS)-oriented operational practices, including reusable delivery infrastructures, staged payload workflows, and backend-supported malware capabilities. This paper presents an exploratory characterization of Brazilian-targeting Android fraud campaigns through the analysis of phishing delivery infrastructures, malware behavior, and operational artifacts. Using OSINT-driven infrastructure discovery, static analysis, DEX-centric reverse engineering, and dynamic execution on physical devices across six real-world Android malware samples, we identified recurring patterns involving fake Google Play-style delivery pages, APK sideloading, PT-BR localized social engineering, Accessibility Services abuse, WebView-supported phishing interactions, staged payload delivery, C2 communication, and anti-analysis mechanisms. The campaigns ranged from phishing-oriented applications to more intrusive malware implementing overlay-capable flows, remote backend communication, and NFC/EMV payment-card interaction capabilities. Cross-sample correlation revealed partially shared protocol logic, reused delivery workflows, and overlapping operational artifacts, suggesting MaaS-oriented development and deployment practices in Brazilian-targeting Android fraud operations.
Referências
Black, P. and Opacki, J. (2016). Anti-analysis trends in banking malware. In 2016 11th International Conference on Malicious and Unwanted Software (MALWARE), pages 1–7.
Botacin, M., Geus, P. d., and Grégio, A. (2020). An empirical study on the blocking of http and dns requests at providers level to counter in-the-wild malware infections. In Anais do Simpósio Brasileiro de Cibersegurança (SBSeg), pages 188–200. SBC.
Bragança, H., Rocha, V., Barcellos, L. V., Souto, E., Kreutz, D., and Feitosa, E. (2023). Capturing the behavior of android malware with mh-100k: A novel and multidimensional dataset. In Anais do Simpósio Brasileiro de Cibersegurança (SBSeg), pages 510–515. SBC.
Damasceno, J. R. F., Bastos, C. A. S., Pereira, F. L. F., Rodrigues, E. B., and Rego, P. A. L. (2026). Replication Package for Characterizing Malware-as-a-Service-Oriented Android Fraud Campaigns Targeting Brazil. Zenodo. Version 1.0.0. DOI: 10.5281/zenodo.21767014.
Etyang, F., Pavithran, P., Mandela, N., and Mwendwa, G. (2025). The evolution and impact of malware-as-a-service (maas) in the dark web: Systematic review. In Proceedings of the 2025 12th International Conference on Computing for Sustainable Global Development (INDIACom), pages 1–7, Delhi, India. IEEE.
Gezer, A., Warner, G., Wilson, C., and Shrestha, P. (2019). A flow-based approach for trickbot banking trojan detection. Computers & Security, 84:179–192.
Karo-Karo, G. F. M., Harumnanda, M. S. A., and Lim, C. (2023). Investigating multiple malware as a service (maas): Analysis and prevention techniques. In 2023 IEEE International Conference on Cryptography, Informatics, and Cybersecurity (ICoCICs), pages 270–274. IEEE.
Kaspersky Securelist (2026). Beatbanker: A dual-mode android trojan. [link]. Accessed: 2026-05-11.
Malik, S., Singh, N., and Tripathy, S. (2026). Semantic characterization of android malware through runtime system call analysis. Journal of Information Security and Applications, 98:104406.
McElroy, S. (2024). Identifying android banking malware through measurement of user interface complexity. In 2024 IEEE International Conference on Cyber Security and Resilience (CSR), pages 348–353. IEEE.
Paganini, P. (2022). Cybercrime-as-a-service: Eu perspectives. In Nestoras, A., Martino, L., and Gamal, N., editors, European Cybersecurity in Context: A Policy-Oriented Comparative Analysis, pages 67–75. European Liberal Forum.
Patsakis, C., Arroyo, D., and Casino, F. (2025). The malware as a service ecosystem. In Gritzalis, D., Choo, K.-K. R., and Patsakis, C., editors, Malware: Handbook of Prevention and Detection, pages 371–394. Springer, Cham.
Schmutz, D., Rapp, R., and Fehrensen, B. (2024). Forensic analysis of hook android malware. Forensic Science International: Digital Investigation, 49:301769.
Silva, C. M. R. d., Teixeira, L. C., Barros, J. C. G. d., Feitosa, E. L., and Garcia, V. C. (2019). Suscetibilidade através da forja de fidedignidade: uma abordagem sobre ataques de phishing. In Anais do Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 139–154. SBC.
