Warning Ghimob new banking malware, mobile users cannot remove

Users need to be very wary of a new type of banking malware called Ghimob that is attacking mobile users globally. 

Kaspersky security has issued a warning about a new type of banking malware - called Ghimob - that is attacking mobile users around the globe.

According to Kaspersky, Guildma is a security threat and is also part of the infamous Tétrade line of malware, known for its destructive activities that have the potential to expand in both Latin America and many countries around the world. They have been very active in the application of new techniques, and developing malware to target new victims.

As a new malware, Trojan Ghimob attacked the banking industry and tricked its victims into installing malicious files through an email message saying that the recipient was in debt.

Warning Ghimob new banking malware, mobile users cannot remove Picture 1

The email also contains a link to trick the victim into clicking into for more information. Once installed, the malware sends a successful infection message to the server.

"Messages include phone number, screen security lock info and a list of installed apps that may be hacked. Overall, Ghimob can spy on 153 mobile apps, mostly are mobile applications from banks, cryptocurrencies and the stock market "- Kaspersky information security expert.

Functionally, Ghimob acts as a spy in the pocket of the victim. Hackers who develop malicious code can easily access infected devices. They commit fraud using the victim's smartphone to avoid device identification and security measures that financial institutions have in place and evade all systems. behavior-based fraud prevention.

Even when the user uses a lock screen, Ghimob can still record and playback to unlock the device. When the hackers develop malicious code ready to commit a fraudulent transaction, they can insert a black screen or open several websites in full screen mode. Then, when the user locks in the screen, the hackers develop malicious code that conduct fraudulent transactions in the background, through financial applications running on the device.

Kaspersky's statistics show that, in addition to Brazil, Ghimob's attack targets are in Paraguay, Peru, Portugal, Germany, Angola and Mozambique and are expanding globally.

Fabio Assolini, Kaspersky's security expert said: 'Ghimob is Brazil's first mobile banking Trojan ready to expand internationally. We think this new campaign may involve Guildma hacker group, responsible for Brazil's famous Trojan malware, especially because they share the same infrastructure.

Kaspersky's security expert recommends that financial institutions closely monitor these security threats, while improving authentication processes, enhancing anti-fraud technology, and data and information. about the security threat and learn about and minimize all the risks posed by this malicious code.

5 ★ | 1 Vote

May be interested

  • Warning: SpyNote phone eavesdropping software is extremely dangerous and difficult to removeWarning: SpyNote phone eavesdropping software is extremely dangerous and difficult to remove
    security researchers at f-secure have just issued a warning about a malware designed to eavesdrop on phones called spynote.
  • Instructions for using Internet Banking VietcombankInstructions for using Internet Banking Vietcombank
    internet banking of vietcombank is a banking service operating through the internet, all customer transactions will be done via an internet-connected computer, refer to the following article of the network administrator to better understand how to use internet banking vietcombank.
  • How to Remove Malware from a MacHow to Remove Malware from a Mac
    this wikihow teaches you how to remove malware from your mac. though macs don't get infected by malware quite as often as pc's, they're not immune to malware attacks. if your mac is infected with malware, the easiest way to remove it is to...
  • Completely remove URL Mal Virus - http://107.170.47.181Completely remove URL Mal Virus - http://107.170.47.181
    url: mal is one of the most dangerous dns related to advertising platform. it has the address is http://107.170.47.181. url: mal is created by free software from unwanted programs (pup). url: mal appears on your computer, then your computer will appear a series of ads. its purpose is to trick users into clicking on links to make a profit.
  • Remove root malware (malware) on Windows 10 computersRemove root malware (malware) on Windows 10 computers
    if pop-up windows are displayed on your windows 10 computer screen or your computer is redirected to advertising windows, it is likely that your computer has adware or chapters. unexpected process of attack.
  • 5 mobile security risks you need to avoid5 mobile security risks you need to avoid
    here are the most used mobile attack methods of 2018. let's find out and see these new digital wave protections.
  • How to check if your PC is infected with Emotet malwareHow to check if your PC is infected with Emotet malware
    emotet is a really nasty type of malware that has been around for years. it was a banking trojan that sneaked into a victim's computer and stole their financial information.
  • How to find and remove WMI Persistence malware from Windows PCsHow to find and remove WMI Persistence malware from Windows PCs
    wmi persistence refers to the attacker installing a script, specifically an event handler, that is always fired when a wmi event occurs.
  • What is FormBook Malware? How to remove?What is FormBook Malware? How to remove?
    if you manage sensitive data, you should be concerned about the formbook malware. once on a network or pc, this information-stealing malware can cause irreparable damage to your company.
  • Steps to remove malware 9o0gle. comSteps to remove malware 9o0gle.  com
    browser attacker www. 9o0gle. com (aka browsermodifier: win32 / heazycrome! blnk) can be installed on your computer without your permission. it can cause serious problems such as slowing down the speed of browsing on your browser, and can monitor users' online activities to sell personal information to third parties.