Detected 4 banking trojans in 11 apps on Google Play Store
Banking Trojans are designed to steal banking credentials and other sensitive data.
Cybersecurity firm ThreatFnai discovered four different banking trojans that were distributed through the Google Play Store itself between August and November 2021. These trojans are distributed through malicious applications that impersonate harmless applications and utilities.
The four trojans in question are Anatsa (aka TeaBot), Alien, ERMAC and Hydra. They are fine-tuned to evade nearly all detection and interception campaigns of the protection system. In just about 3 months, these 4 trojans have spread to over 300,000 devices.
Here is a list of apps that contain banking trojans:
- Two Factor Authenticator (com.flowdivison)
- Protection Guard (com.protectionguard.app)
- QR CreatorScanner (com.ready.qrscanner.mix)
- Master Scanner Live (com.multifuction.combine.qr)
- QR Scanner 2021 (com.qr.code.generate)
- QR Scanner (com.qr.barqr.scangen)
- PDF Document (com.xaviermuches.docscannerpro2)
- Scanner - Scan to PDF
- PDF Document Scanner (com.docscanverifier.mobile)
- PDF Document Scanner Free (com.doscanner.mobile)
- CryptoTracker (cryptolistapp.app.com.cryptotracker)
- Gym and Fitness Trainer (com.gym.trainer.jeux)
Earlier this month, Google introduced limits to restrict the use of accessibility permissions to allow malicious apps to collect sensitive data from Android devices. However, the malware developers have tweaked their tactics to be able to attack even when forced to install according to the traditions, through the official app stores.
One of the most sophisticated tactics is called versioning. Initially, a clean version with standard functionality of the application will be uploaded to the app store. Then, the malicious code will be introduced gradually through updates.
If you find these applications on your phone, you should remove them immediately to avoid future damage.
- Download Google Play 24.2.15-16
- Fix Google Play Store not opening and downloading apps
- Google declined to add 55% of the new Android application to Play Store in 2018, but that's not enough!
- Google is determined to prevent bad apps before they reach users on the Play Store
- How to identify and avoid fake Android apps in Play Store
- How to pay for apps on Google Play with Mobifone account