Fake National Health Service Site Delivers StreamRat on Android and XWorm on Windows

· Original article ↗

Summary

CERT-AGID analyzed a fake Italian National Health Service site that serves StreamRat to Android devices and an obfuscated PowerShell loader leading to XWorm on Windows. StreamRat can receive targets and HTML overlays dynamically from its server.

Key points

  • The fake site uses the National Health Service name and appearance as a lure and serves different malware based on the visitor’s browser User-Agent.
  • On Android, SSN.apk decodes and installs a second APK containing StreamRat, which prompts users to enable Accessibility services.
  • StreamRat can read and control the device interface, capture screens, run commands, and display attacker-supplied HTML overlays to collect entered information.
  • StreamRat reports the foreground app to its server, which can select targets and supply overlays dynamically without requiring the malware to be redistributed.
  • On Windows, SSN Windows.bat launches hidden PowerShell, retrieves a file disguised as 2.jpg, and loads a .NET assembly in memory before the chain delivers XWorm.
  • The Android and Windows branches use different malware but both aim to provide attackers with extensive remote access to compromised devices.
  • CERT-AGID published indicators of compromise for the campaign.

Article Details

Attack Vectors
  • A fake Servizio Sanitario Nazionale page selects a download based on the visitor's browser User-Agent: SSN.apk for Android or SSN Windows.bat for Windows.
  • The Android APK decodes and installs a second APK containing StreamRat. The app presents a false update request and asks the user to enable Android Accessibility services.
  • StreamRat can receive commands over WebSocket on TLS, control the device interface, capture its screen, and display remotely supplied HTML overlays to collect information entered by the user.
  • The Windows BAT file launches a hidden PowerShell instance. It retrieves a file named 2.jpg, decodes a Base64-encoded .NET executable from its contents, loads it in memory, and ultimately leads to XWorm execution.
Defensive Notes
  • The purported SSN app's request for Android Accessibility access is a significant warning sign: the analyzed malware uses that access to observe and control the interface.
  • The SSN branding is an installation lure, not evidence that subsequent malicious activity targets only healthcare services; the Android malware can receive overlay targets dynamically.

MITRE ATT&CK

Malware

Products

Related Articles