Android software specialized in stealing bank passwords, copying keystrokes
Cybereason, a security company, discovered malware on the Android platform and named it EventBot. According to THN , EventBot has the ability to target 200 different financial applications including banking software, money transfer services, encrypted e-wallets such as Paypal Business, Revolut, Barclays, CapitalOne, HSBC, Santander, TransferWise, Coinbase.
The representative of the research team said that this malicious application is particularly interested in the above software because they are quite new and somewhat rudimentary. 'This new type of malware actually has the potential to become a more dangerous version of malware on mobile phones because it is constantly improving, abusing critical operating system features and targeting malicious applications. main ', the team at Cybereason said.
The attack campaign using EventBot was first discovered in March 2020, disguised as legitimate software (such as Adobe Flash, Microsoft Word), and appeared on fake Android app stores (which often contained APK file for installing applications on this platform) or non-transparent websites. After installation, the program will require additional permissions on the device.
Permissions required include access to Settings, the ability to read content on an external memory card, send and receive SMS messages, run in the background, and start automatically after the system is rebooted. If the user grants the required permissions, the EventBot starts to record keystrokes that the user manipulates on the screen, collecting notifications when other applications are installed and viewing content from the program. open on screen.
EventBot can also exploit Android accessibility services to collect screen lock codes and then transfer all the collected data in encrypted form to the server controlled by the attacker.
The ability to analyze SMS messages (text messages) gives this application a useful tool to bypass two-step security steps using SMS, giving hackers access to cryptocurrency wallets and theft account in the victim's bank easily.
Suspicious applications such as EventBot may not exist on the official Google Play Store, so researchers once again recommend that users install the program only for phones from official software stores. , avoid downloading and installing from other untrusted sources.
This is not the first time mobile malware has been targeted on financial services. Last month, IBM's X-Force team announced a campaign called TrickMo by hackers targeting users in Germany, using malware that takes advantage of the Accessibility feature on phones to block and read one-time passwords (OTP), mTAN and pushTAN authentication codes (banking-related services in Germany).
5 ★ | 1 Vote
You should read it
- Appearing dangerous Android malicious code specializing in stealing chat content on Facebook Messenger, Skype ...
- 14 games on the App Store contain malicious code, iPhone users be careful
- Detect new malicious code to attack Android device
- Find bug in Emotet malware, prevent it from spreading for 6 months
- A serious security error appeared on Android that allowed hackers to control smartphones through a photo
- The malicious video file causes users to lose control of the device 'storming' in the Android world
- Embed malicious code into PDF file without security error
- 238 applications found on Play Store contain malicious code that paralyzes smartphones
May be interested
- Is someone monitoring your keyboard presses?keyloggers can steal account names, passwords, and banking information without ever alerting you—which is why you should regularly check your computer for this nasty type of malware.
- New malware discovered to steal bank accountssecurity experts at trend micro have just discovered a type of malware called mmrat that can take control of phones and steal money from bank accounts.
- List of 203 money-stealing applications that iPhone and Android users should urgently deletebelow is a list of 203 malicious applications on android and ios platforms that have the ability to collect personal information, steal bank accounts and take control of users' devices.
- 7 tips to avoid information theftonline payment - including online payment, bank card services ..., is becoming more and more popular in our country. attached to the convenience is the risk of stealing personal information about accounts, passwords ...
- Shinhan Bank is good?this article will clarify the information of shinhan bank, including personal, business support services and the list of shinhan bank branches in vietnam.
- LokiBot - bank trojan on Android turns into ransomware when you try to delete itsecurity agents have discovered a new bank trojan on android called lokibot that turns into extortion code and locks the phone when the user tries to delete its admin rights.
- New bank trojan detection on Android Red Alertnetwork security researchers have discovered a new android banking trojan called red alert 2.0 that has been developed for the past few months and has just been launched.
- Android SDK - Download Latest Android SDKandroid sdk is a free and specialized programming language that allows you to create android applications.
- 151 Android apps that steal money in your account, you should remove it immediately if you accidentally install itsecurity researchers have discovered 151 android apps that steal money from users' accounts.
- Warning: Android fake Uber software appears to trick user passwordssecurity firm symantec has discovered a new malware with a fake uber application interface aimed at android, via pop-ups that require user login and password information to trick them.