Security researchers at ESET have discovered a new Android Trojan that has the potential to cause considerable monetary damage to users. As per WeLiveSecurity, a new Android malware can steal money from a victim’s PayPal account, even with 2-Factor Authentication (2-FA) turned on. The trojan has been disguised as a battery optimisation app called “Optimization Android,” which is being distributed via third-party online app stores and not the Google Play Store. Once the app is installed and launched, it will boot and close immediately. Then, the user will be requested to grant Accessibility permission, which will give the app complete authority but this process is masqueraded as “enable statistics.” Lukas Stefanko from WeLiveSecurity also posted a video of the trojan in action. In the video below, you will notice that the app sends a notification to the user after it’s installed, which states “Confirm your account immediately.” Tapping on the notification boots up the official PayPal application on their phone and any unsuspecting user would sign-in like they would normally do, even with the 2-FA enabled. However, as soon as the user signs in, the trojan then automatically fast forwards through the money transfer process by emulating taps, which it can do so because of the access to accessibility service. In the video below, you might notice that it automatically sends $100,000 to the attacker’s PayPal address. The malware is said to change the currency used based on a user’s location. Android Trojan makes PayPal payment on behalf of user. It sends $1,000 from victim's account every time user opens PayPal app.https://t.co/942rAYv0NT pic.twitter.com/h2fdGui5Y2 — Lukas Stefanko (@LukasStefanko) December 11, 2018 The Trojan takes less than five seconds to automatically send money from the victim’s PayPal account. As per WeLiveSecurity, the process is only halted if the user has not linked any payment card to the account or if there’s insufficient PayPal balance. Additionally, the trojan’s malicious Accessibility service keeps waiting in the background and activates as soon as the PayPal app is booted. This means that it can automatically transfer money from the victim’s account multiple times. WeLiveSecurity has reported this malicious technique to PayPal, along with the account used by the attacker to receive stolen funds. There’s also an additional method by which the trojan can steal user’s credentials. It uses a screen overlay that draws over apps like Google Play, Skype, WhatsApp, and others that ask users for their payment information. When users enter their credit card details, the overlay attempts to steal the information. Do note that an invalid input is also accepted by the overlay and it disappears. However, there’s still a chance of user’s data being stolen if they enter the correct details on the first go. As mentioned earlier, the trojan is not on the Google Play Store and thus, there’s a lesser chance of users falling a victim to it. Unless, of course, you download apps from third-party websites. WeLiveSecurity suggests that one turns off third-party app installs on their phone and download apps only from the official Android app market.
from Latest Technology News https://ift.tt/2LctSXb
flipkart
Subscribe to:
Post Comments (Atom)
flipkart
Edit videos on your mobile phone using the YouTube Create App
YouTube has introduced its new mobile app called ‘YouTube Create’. This app offers an easy way for creators to edit their videos right from ...
- September 2023 (83)
- August 2023 (126)
- July 2023 (113)
- June 2023 (102)
- May 2023 (162)
- April 2023 (160)
- March 2023 (148)
- February 2023 (136)
- January 2023 (173)
- December 2022 (163)
- November 2022 (163)
- October 2022 (181)
- September 2022 (178)
- August 2022 (174)
- July 2022 (136)
- June 2022 (125)
- May 2022 (146)
- April 2022 (130)
- March 2022 (143)
- February 2022 (132)
- January 2022 (145)
- December 2021 (157)
- November 2021 (239)
- October 2021 (269)
- September 2021 (270)
- August 2021 (212)
- July 2021 (252)
- June 2021 (225)
- May 2021 (184)
- April 2021 (181)
- March 2021 (343)
- February 2021 (299)
- January 2021 (320)
- December 2020 (334)
- November 2020 (305)
- October 2020 (318)
- September 2020 (340)
- August 2020 (347)
- July 2020 (337)
- June 2020 (310)
- May 2020 (308)
- April 2020 (418)
- March 2020 (316)
- February 2020 (282)
- January 2020 (329)
- December 2019 (323)
- November 2019 (393)
- October 2019 (403)
- September 2019 (386)
- August 2019 (454)
- July 2019 (579)
- June 2019 (509)
- May 2019 (697)
- April 2019 (725)
- March 2019 (746)
- February 2019 (702)
- January 2019 (932)
- December 2018 (758)
- November 2018 (729)
- October 2018 (835)
- September 2018 (838)
- August 2018 (548)
- March 2018 (24)
-
Huawei, it seems, cannot seem to steer away from controversy around its smartphones’ camera capabilities. This time, a Chinese photographer ...
-
Now that the first Developer Preview of the next version of Android has gone live, we can expect to see more and more reports of upcoming fe...
-
Apple is reportedly using Qualcomm modem and its own technology to provide satellite communications Emergency SOS feature on new iPhone 14 s...
No comments:
Post a Comment