Detecting fake 2FA security apps that can steal bank accounts on Android phones
Two-factor authentication (2FA), which is a simple and effective form of security, is therefore widely used in today's digital verification activities. However, it is that popularity that gives hackers the idea of using 2FA to serve their malicious purposes.
International security researchers have just discovered a dangerous fake two-factor authentication application on the Android platform. Inside this application hides a type of malicious code in the form of a banking trojan, capable of stealing financial data and other personal information when successfully installed on the victim's device.
Pradeo was the first security team to detect this malicious application. It is aptly named 2FA Authenticator to make itself more 'reputable', which contains a type of trojan called Vultur. This Trojan can infect Android phones as soon as the 2FA Authenticator app is successfully installed. According to the investigation of security experts, this malicious application has existed for more than a year, and has received no less than 10,000 installs on Google Play.
'Our analysis shows that the app automatically installs a piece of malware called Vultur, which targets financial services to steal users' banking information.
The interface of this fake application is generally quite well designed, looking exactly like a legitimate 2FA tool, enough to fool the majority of ordinary users. According to the Pradeo team, '2FA Authenticator looks legit and offers a real 2-factor security service. To do so, its developers used the open source code of the official Aegis authentication app, and injected malicious code into it'.
The 2FA Authenticato app works in two phases. First, it profiling the user, by collecting and sending the victim's application list and location data. During this phase, the malware disables the keylock and any associated form of password security, then downloads other third-party apps disguised as updates.
In stage two, researchers discovered that the attack depends on information the application finds about the user in phase 1. When certain conditions are met, Vultur is installed, the The malware primarily targets online banking interfaces to steal credentials and financial information'.
This is not a piece of malware disguised as a security tool and taken lightly. If you already have this app installed (removed from Google Play but still available on some third-party app stores), you need to remove it immediately. If the app starts to relaunch itself when you try to close it, restart your phone and remove it from the system.
You should read it
- Applications create authentication codes on Windows 10
- Use SEO to bring Google search results to bank trojans
- Authenticate what two factors are and why you should use it
- How to enable two-factor authentication for Threads accounts
- Protect your GitHub account with two-factor authentication
- Google 'purged' 24 applications downloaded nearly 500,000 times containing malicious malware
- How to turn on two-factor authentication to protect your Firefox account
- Detects many malicious Android applications that hide icons themselves to make it harder to uninstall
May be interested
- Top 10 most dangerous malware types with bank accountszeus, spyeye, ice ix or citadel are notorious malware software that can infiltrate user computers, poison and steal personal information and financial data on online bank accounts. online.
- Malware can steal Facebook, Twitter and Gmail accountsresearchers have discovered a new and complex malware variant, based on the famous zeus bank trojan but not just stealing bank accounts.
- One in three smartphone users will encounter malicious banking applicationsthe results of a global study conducted by avast network security company and published at mwc 2018 showed that 36% of survey respondents could not tell the difference between a fake bank application and a real application.
- Anyone must memorize these golden rules to secure bank accountsit is undeniable that online banking accounts are quite useful and convenient to help users make transactions quickly and save time. however, there are also risks that users cannot anticipate, such as exposed atm passwords or certain situations.
- Instructions on how to fake ip on Androidfake ip gives us many benefits: anonymizing your real ip address to prevent bad guys from accurately detecting your address, accessing blocked websites or services in the host country ... today, let's find out how to fake ip on android.
- Strandhogg vulnerability on Android allows malicious code to impersonate every Android applicationsecurity firm promon recently discovered a new vulnerability, called strandhogg, that exists in android's multi-tasking feature.
- Detecting new malware on Android can damage phonesunlike other malware (malware) that only steal data, when entering android and loapi phones, the hardware must work overload causing serious damage.
- How to detect malicious apps on Androidinstalling applications outside of google play is often potentially risky, making users more likely to steal personal data and money. therefore, the detection of malicious applications on android phones will help you distinguish what will be a safe application, where the application contains malicious code, thereby minimizing the download of dangerous applications. security and protection of android devices become safer.
- Stolen bank account with Trojan Bankingtoday with the development of the digital age, online banking transactions are no longer strange. and the malware developer has released a kind of trojan used to steal users' bank accounts.
- Trojan, threat of financial securitytechnology criminals will be online with you in transactions to steal money. the warning of experts on a new situation worrisome in financial transaction security. trojans stealing accounts are operating very violently. this software will hide & igr