Thursday, January 30, 2025
HomeMalwareBanking Malware posed as a Popular Social Media App to Steal Financial...

Banking Malware posed as a Popular Social Media App to Steal Financial Data From Online Banking Systems

Published on

SIEM as a Service

Follow Us on Google News

Newly discovered Two Android Banking Trojan posed as popular social Media and banking apps to steal the victim’s financial information from online banking and payment systems

Android Banking Trojan’s mainly targeting the financial sector such as bank and other financial institutions and compromising it to steal sensitive information such as username, password and credit card data.

It mimics as popular social media apps such as WhatsApp, Facebook, Skype, Instagram, Twitter and other India based banking apps.

Malicious Android Applications are using fake ICON’s to trick users to install it on to the victim’s device.

How Does This Banking Trojan Attack Works

Initially victims download the malicious apps downloaded from third-party app stores or links provided in SMS’s or emails and pornographic websites.

Once it downloads and installed into the vicitms computer the malware gain access to special privileges by forcing the user to select the ‘Activate’ button.

The malicious application requested to Activate the device administrator to gain the complete control of the infection victims device.

If the user will press the CANCEL button, the app will keep asking Press the ACTIVATE  button to gain the special permission as you can see the above Picture.

Also, this malware having a list of apps that imitate as a legitimate apps and search it in the infected victim’s device after gaining the special permission.

According to Quickheal,  if the user opens any of these apps (banking or social media), the Trojan displays a fake window asking for a credit/debit card number. Unless this number is provided, this window prevents the user from accessing the app

Once the infected users will provide a card number and other relevant information that requested by this Trojan, then it will share the gathered information to the attacker via Command & Control server.

Mitigation

  1. Avoid downloading apps from third-party app stores or links provided in SMS or emails.
  2. Always keep ‘Unknown Sources’ disabled. Enabling this option allows installation of apps from third-party sources.
  3. Keep Play Protection service ‘ON’
  4. Verify app permissions before installing any app even from official stores such as Google Play.

Also Read:

Dangerous PANDA Banking Malware Spreads Through Phishing Attacks Targets Banks, Cryptocurrency Sites and Social Media

New Malicious dropper Spreading Dangerous “Bankbot” Banking Malware via Google Play store

New Dangerous Android Permission Security Flaw leads to Ransomware and Banking Malware Attacks

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently...

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton...

Arcus Media Ransomware Strikes: Files Locked, Backups Erased, and Remote Access Disabled

The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

Hackers Impersonate Top Tax Firm with 40,000 Phishing Messages to Steal Credentials

Proofpoint researchers have identified a marked increase in phishing campaigns and malicious domain registrations...

Lazarus Group Drop Malicious NPM Packages in Developers Systems Remotely

In a recent discovery by Socket researchers, a malicious npm package named postcss-optimizer has...