November 1, 2018 By Shane Schick 2 min read

Nearly 30,000 Android users accidentally downloaded banking malware after being tricked by personalized phishing forms based on the apps they use.

Google removed 29 malicious apps from its Play Store after learning about the threat, according to a report from ESET. Although the apps were attributed to different developers, the researchers discovered enough common code to suggest that they were all created by the same malware author or threat group.

The malware enables the attackers to send and receive text messages on infected Android devices, which allows them to get past multifactor authentication (MFA) protocols that might otherwise have protected the user’s banking data. The malware can also impersonate software from victims’ financial institutions and download additional apps to compromised devices.

A Unique Approach to Distributing Banking Malware

Creating phony versions of banking sites is one of the oldest phishing schemes in the book, but these attackers took a more subtle approach. They scanned the other, legitimate apps on the device, grabbed some HTML code and used it to create a tailor-made form to fool victims with bogus error messages.

Some victims received a notification that their app was no longer compatible with their device and had been removed, for instance. Meanwhile, the attackers used a dropper to check for sandboxes and emulators. If they didn’t find any, a loader was decrypted with a payload containing the banking malware.

The 29 malicious apps included popular utilities such as battery managers, device boosters and cleaners, the researchers noted. Others, such as phony horoscope apps, targeted users seeking casual entertainment.

The Case For Client-Based Fraud Detection

People tend to be pretty fast on their smartphones, which means there may not be a lot of time between the moment a user downloads an app with a banking Trojan and when the payload is executed.

IBM experts recommend investing in client-side fraud detection to close this gap, along with technology that can identify malicious apps as early as possible. Given how easily cybercriminals can not only replicate banking sites but create a one-to-one approach with personalized forms, organizations will need to be ready to adapt to new phishing techniques faster than ever.

Source: ESET

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today