• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
fake indian banking rewards apps targeting android users with info stealing

Fake Indian Banking Rewards Apps Targeting Android Users with Info-stealing Malware

You are here: Home / General Cyber Security News / Fake Indian Banking Rewards Apps Targeting Android Users with Info-stealing Malware
September 23, 2022

An SMS-based phishing marketing campaign is targeting prospects of Indian banking institutions with info-stealing malware that masquerades as a benefits application.

The Microsoft 365 Defender Study Team mentioned that the messages have inbound links that redirect people to a sketchy internet site that triggers the obtain of the pretend banking benefits app for ICICI Bank.

“The malware’s RAT capabilities allow the attacker to intercept important product notifications these as incoming messages, an apparent effort to catch two-factor authentication (2FA) messages often made use of by banking and economical establishments,” scientists Shivang Desai, Abhishek Pustakala, and Harshita Tripathi said.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


CyberSecurity

Also, the malware is equipped with the potential to steal SMSes, probably enabling the attacker to swipe 2FA codes sent as text messages and attain unauthorized entry to victim accounts.

Like other social engineering attacks, familiar brand logos and names are applied in the smishing information as effectively as the rogue application in a bid to give an illusion of legitimacy and trick the end users into putting in the applications.

Fake Indian Banking Rewards Apps

The attacks are also a continuation of an ongoing marketing campaign that has dispersed comparable rewards-themed applications for other Indian banking institutions these kinds of as the Point out Lender of India (SBI) and Axis Bank in the earlier.

After put in, the fraudulent app not only asks for intensive permissions, but also requests customers to enter their credit score/debit card information as element of a meant indication-in procedure, while the trojan waits for even further directions from the attacker.

CyberSecurity

These instructions allow for the malware to harvest method metadata, connect with logs, intercept phone calls, as properly as steal credentials for email accounts this sort of as Gmail, Outlook, and Yahoo.

“This malware’s continuing evolution highlights the need to protect mobile equipment,” the scientists stated. “Its broader SMS thieving capabilities could allow attackers to the stolen data to even further steal from a user’s other banking apps.”

Found this short article intriguing? Stick to THN on Facebook, Twitter  and LinkedIn to study a lot more special written content we post.


Some pieces of this post are sourced from:
thehackernews.com

Previous Post: «podcast transcript: meet the cyborg hacker Podcast transcript: Meet the cyborg hacker
Next Post: Europol “Hackathon” Identifies Scores of Human Trafficking Victims Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections
  • Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts

Copyright © TheCyberSecurity.News, All Rights Reserved.