Warning Ghimob new banking malware, mobile users cannot remove
Users need to be very wary of a new type of banking malware called Ghimob that is attacking mobile users globally.
Kaspersky security has issued a warning about a new type of banking malware - called Ghimob - that is attacking mobile users around the globe.
According to Kaspersky, Guildma is a security threat and is also part of the infamous Tétrade line of malware, known for its destructive activities that have the potential to expand in both Latin America and many countries around the world. They have been very active in the application of new techniques, and developing malware to target new victims.
As a new malware, Trojan Ghimob attacked the banking industry and tricked its victims into installing malicious files through an email message saying that the recipient was in debt.
The email also contains a link to trick the victim into clicking into for more information. Once installed, the malware sends a successful infection message to the server.
"Messages include phone number, screen security lock info and a list of installed apps that may be hacked. Overall, Ghimob can spy on 153 mobile apps, mostly are mobile applications from banks, cryptocurrencies and the stock market "- Kaspersky information security expert.
Functionally, Ghimob acts as a spy in the pocket of the victim. Hackers who develop malicious code can easily access infected devices. They commit fraud using the victim's smartphone to avoid device identification and security measures that financial institutions have in place and evade all systems. behavior-based fraud prevention.
Even when the user uses a lock screen, Ghimob can still record and playback to unlock the device. When the hackers develop malicious code ready to commit a fraudulent transaction, they can insert a black screen or open several websites in full screen mode. Then, when the user locks in the screen, the hackers develop malicious code that conduct fraudulent transactions in the background, through financial applications running on the device.
Kaspersky's statistics show that, in addition to Brazil, Ghimob's attack targets are in Paraguay, Peru, Portugal, Germany, Angola and Mozambique and are expanding globally.
Fabio Assolini, Kaspersky's security expert said: 'Ghimob is Brazil's first mobile banking Trojan ready to expand internationally. We think this new campaign may involve Guildma hacker group, responsible for Brazil's famous Trojan malware, especially because they share the same infrastructure.
Kaspersky's security expert recommends that financial institutions closely monitor these security threats, while improving authentication processes, enhancing anti-fraud technology, and data and information. about the security threat and learn about and minimize all the risks posed by this malicious code.
You should read it
- Detected 4 banking trojans in 11 apps on Google Play Store
- Destroy ZeuS, the 'lord' of banking trojans
- Microsoft warned the Emotet trojan back on a large scale, stealing the victim's banking information
- Use SEO to bring Google search results to bank trojans
- How to check if your PC is infected with Emotet malware
- New bank trojan detection on Android Red Alert
- Risks from malware and how to prevent it
- Sophisticated spam Trojan unmatched
May be interested
- Warning: SpyNote phone eavesdropping software is extremely dangerous and difficult to removesecurity researchers at f-secure have just issued a warning about a malware designed to eavesdrop on phones called spynote.
- Instructions for using Internet Banking Vietcombankinternet banking of vietcombank is a banking service operating through the internet, all customer transactions will be done via an internet-connected computer, refer to the following article of the network administrator to better understand how to use internet banking vietcombank.
- How to Remove Malware from a Macthis wikihow teaches you how to remove malware from your mac. though macs don't get infected by malware quite as often as pc's, they're not immune to malware attacks. if your mac is infected with malware, the easiest way to remove it is to...
- Completely remove URL Mal Virus - http://107.170.47.181url: mal is one of the most dangerous dns related to advertising platform. it has the address is http://107.170.47.181. url: mal is created by free software from unwanted programs (pup). url: mal appears on your computer, then your computer will appear a series of ads. its purpose is to trick users into clicking on links to make a profit.
- Remove root malware (malware) on Windows 10 computersif pop-up windows are displayed on your windows 10 computer screen or your computer is redirected to advertising windows, it is likely that your computer has adware or chapters. unexpected process of attack.
- 5 mobile security risks you need to avoidhere are the most used mobile attack methods of 2018. let's find out and see these new digital wave protections.
- How to check if your PC is infected with Emotet malwareemotet is a really nasty type of malware that has been around for years. it was a banking trojan that sneaked into a victim's computer and stole their financial information.
- How to find and remove WMI Persistence malware from Windows PCswmi persistence refers to the attacker installing a script, specifically an event handler, that is always fired when a wmi event occurs.
- What is FormBook Malware? How to remove?if you manage sensitive data, you should be concerned about the formbook malware. once on a network or pc, this information-stealing malware can cause irreparable damage to your company.
- Steps to remove malware 9o0gle. combrowser attacker www. 9o0gle. com (aka browsermodifier: win32 / heazycrome! blnk) can be installed on your computer without your permission. it can cause serious problems such as slowing down the speed of browsing on your browser, and can monitor users' online activities to sell personal information to third parties.