WWW.SOLUTIONFANS.COM - MASTER OF ALL EXAM RUNS

Home
Stories
News
Edu
Notorious Android malware that will drain your bank account discovered on Google app store - solutionfans.com
   

  • Notorious Android malware that will drain your bank account discovered on Google app store - solutionfans.com
  • Share
    Tweet
    Whatsapp
    Mail

    BankBot Trojan disguised as ‘Jewels Star Classic’ game had up to 5,000 downloads.

    BankBot is a notorious banking Trojan which targets Android devices

    An notorious Android Trojan known as “BankBot” was recently discovered posing as a gaming application on the Google Play Store. It had thousands of downloads before being successfully purged from the marketplace, security researchers have revealed.

    Experts from Eset, a Slovakian security company, said this week (25 September) that the Trojan – which aims to steal credit card details – had been spotted using a number of “new tricks” that move away from posing as banking apps in favour of targeting Google Play itself.

    The new campaign, discovered on 4 September, impacted users who thought they were downloading a game titled “Jewels Star Classic”, a blog post stated.

    Before being booted from the marketplace by Google, the Trojan had been downloaded up to 5,000 times.

    BankBot was first analysed by Russian cybersecurity experts from “Dr Web” in December last year.

    In January, the researchers confirmed that its source code had leaked online – causing a spike in activity.

    Now, the evolved strain is able to abuse Google’s legitimate “Accessibility Services” and better hide in smartphones and tablets.

    Users who downloaded the gaming app would indeed get a functioning product, but after 20 minutes (a method of evading Google’s anti-malware scans) it would turn nasty.

    After this pre-set delay, the new BankBot Trojan demanded the victim accept a screen prompt to enable a mysterious function called “Google Service” – only escapable by clicking OK.

    The user is taken to a legitimate menu screen, where the malware had inserted a fake button.

    If the user activated the malicious service, which was not affiliated with Google, the hacker would essentially be granted access to a slew of invasive permissions.

    As Eset detailed in its report, the move would give the Android Trojan “a free hand to carry out any tasks it needs to continue its malicious activity”.

    A pop-overlay screen would claim the phone was updating but, in reality, the hackers were covering up BankBot’s true activity – granting themselves access to elevated permissions.

    They would then be able to install other apps, launch the Trojan and intercept messages.

    Prior BankBot versions found in the wildwould mirror popular banking applications in the hope that victims wouldn’t realise, and enter their account passwords.

    This time, however, it targeted Google Play by overlaying the real app with a form which asked unwitting users to enter financial details to continue using the service.

    “If the user falls for the fake form and enters their credit card details, the attackers have essentially won,” the researchers warned.

    BankBot

    The BankBot malware was posing as ‘Jewels Star Classic’ on Google Play Store

    They said that the ability to intercept text messages would let the cybercriminals bypass two-factor authentication, which is often be the last line of defence in this scenario.

    “The crooks have put together a set of techniques with rising popularity among Android malware authors: abusing Android Accessibility Service, impersonating Google, and setting a timer delaying the onset of malicious activity to evade Google’s security measures,” Eset said.

    “The techniques combined make it very difficult for the victim to recognise the threat in time.”

    It remains unknown who is behind the BankBot campaigns – but as the source code is available online it is highly likely that a variety of people have adapted its code for criminal use.

    To stay safe from banking Trojans and other malicious software, Android users are advised to only download apps from legitimate sources and remain vigilant when any software asks you to input personal passwords or financial information into suspicious login forms.

    Read: How To Get And Earn Free Airtime On GeoPoll App 



    If you like this story, please share it on Facebook, Twitter, Google+, Pinterest ETC.
    also don't forget to leave a Reply, we would very MUCH appreciate Your Comments On This Post Below. Thanks!
    Master Solution October 2, 2017 Categories: Tech 538


    Related Posts In » Tech
    Simple things you should do ,when you have a low car battery
    12 secret tips to enhance your programming skill.
    Dangerous Mistakes Everyone Should Avoid When Cooking With Gas
    Common Mistakes People Make While Charging Their Phones which could lead to Damaged Battery
    MAKE MONEY FROM THE COMFORT OF YOUR HOME.
    Reasons You Should Check Your Email Spam Folder Every Day
    How To Get FREE AIRTEL 35MB
    HOW TO GET FREE AIRTIME FROM AIRTEL NOW! UP TO N3000
    HOW TO GET FREE 5GB/10GB OR 20GB FROM AIRTEL FOR BROWSING ON BOTH PC,LAPTOP AND MOBILE
    HOW TO ACTIVATE THE MTN FREE BONUS PACKAGE FOR NEWBIES
    HOW TO USE BLACKBERRY BIS SUBSCRIPTION TO BROWSE ON YOUR PC/LAPTOP
    Airtel New Code for Subscribing to 1GB BIS Bundle
    Paypal Partner With First Bank Nigeria
    » See More Posts in- Tech
    Be The First To Add A Comment
    Leave a comment
    Click here to cancel reply.

     Disclaimer                
    Comments, Pictures and culled stories posted on this website will be given due credit and is not the fault of Solutionfans.com if they are given original credit from site culled from. If you have a complaint or a story, Please Send To Us Via [email protected]
    Top
    Forum
    Contact
    © 2018 Solutionfans.com
    © 2016 - solutionfans.com Inc