Over 300,000 Android users have downloaded these banking trojan malware apps, say security researchers (2024)

Over 300,000 Android smartphone users have downloaded what turned out to be banking trojans after falling victim to malware that has bypassed detection by the Google Play app store.

Detailed bycybersecurity researchers at ThreatFabric, the four different forms ofmalwareare delivered to victims via malicious versions of commonly downloaded applications, including document scanners, QR code readers, fitness monitors and cryptocurrency apps. The apps often come with the functions that are advertised in order to avoid users getting suspicious.

ZDNET Recommends

In each case, the malicious intent of the app is hidden and the process of delivering the malware only begins once the app has been installed, enabling them to bypass Play Store detections.

SEE:A winning strategy for cybersecurity(ZDNet special report)

The most prolific of the four malware families is Anatsa, which has been installed by over 200,000 Android users – researchers describe it as an "advanced"banking trojanthat can steal usernames and passwords, and uses accessibility logging to capture everything shown on the user's screen, while a keylogger allows attackers to record all information entered into the phone.

Anasta malwarehas been active since January, but appears to have received a substantial push since June – researchers were able to identify six different malicious applications designed to deliver the malware. These include apps that posed as QR code scanners, PDF scanners and cryptocurrency apps, all of which deliver the malware.

One of these apps is a QR code scanner, which has been installed by 50,000 users alone, and the download page features a large number of positive reviews, something that can encourage people to download the app. Users are directed to the apps viaphishing emailsormalicious ad campaigns.

After the initial download, users are forced to update the app to continue using it – it's this update that connects to a command and control server and downloads the Anatsa payload onto the device, providing attackers with the means to steal banking details and other information.

The second most prolific of the malware families detailed by researchers at ThreatFabric is Alien,an Android banking trojanthat can also steal two-factor authentication capabilities and which has been active for over a year. The malware has received 95,000 installations via malicious apps in the Play Store.

One of these is a gym and fitness training app that comes with a supporting website designed to enhance the legitimacy, but close inspection of the site reveals placeholder text all over it. The website also serves as the command and control centre for the Alien malware.

Like Anasta, the initial download doesn't contain malware, but users are asked to install a fake update – disguised as a package of new fitness regimes – which distributes the payload.

The other two forms of malware that have been dropped using similar methods in recent months are Hydra andErmac,which have a combined total of at least 15,000 downloads. ThreatFabric has linked Hydra and Ermac to Brunhilda, a cyber-criminal group known to target Android devices with banking malware. Both Hydra and Ermac provide attackers with access to the device required to steal banking information.

SEE: The IoT is getting a lot bigger, but security is still getting left behind

ThreatFabric has reported all of the malicious apps to Google and a Google spokesperson confirmed to ZDNet that the apps named in the report have been removed from the Play Store. Cyber criminals will continually attempt to find ways to bypass protections to deliver mobile malware, which is becoming increasingly attractive to cyber criminals.

"The Android banking malware echo-system is evolving rapidly. These numbers that we are observing now are the result of a slow but inevitable shift of focus from criminals towards the mobile landscape. With this in mind, the Google Play Store is the most attractive platform to use to serve malware," Dario Durando, mobile malware specialist at ThreatFabric, told ZDNet.

The convincing nature of the malicious apps means that they can be hard to identify as a potential threat, but there are steps users can take to avoid infection

"A good rule of thumb is to always check updates and always be very careful before granting accessibility services privileges – which will be requested by the malicious payload, after the "update" installation – and be wary of applications that ask to install additional software," said Durando.

MORE ON CYBERSECURITY

Over 300,000 Android users have downloaded these banking trojan malware apps, say security researchers (2024)

FAQs

Over 300,000 Android users have downloaded these banking trojan malware apps, say security researchers? ›

Over 300,000 Android users have downloaded these banking trojan malware apps, say security researchers. Cybersecurity researchers at ThreatFabric detail how password-stealing Android banking trojans were disguised as QR code readers, fitness monitors, cryptocurrency apps and more.

How to remove Trojan virus from Android for free? ›

How Do I Completely Remove Malware from Android?
  1. Step 1: Immediately Turn Your Phone Off Before Performing Some Research. ...
  2. Step 2: Turn the Phone On in Safe Mode or Emergency Mode. ...
  3. Step 3: Go to Device Settings to Locate the Malicious App. ...
  4. Step 4: Uninstall the Infected Application. ...
  5. Step 5: Opt For A Factory Reset.

What is the new Android Trojan malware? ›

Cybersecurity researchers have discovered an updated version of an Android banking trojan called Medusa that has been used to target users in Canada, France, Italy, Spain, Turkey, the U.K., and the U.S.

Is Trojan virus harmful for Android? ›

Impact. Once the trojan is installed on the device, it silently performs its actual, unauthorized functions, which may range from harvesting personal data from the device, to sending premium SMS messages or intercepting SMS messages, connecting the device to a botnet and so on.

How many Android apps have malware? ›

Many pose as PDF or QR code readers and install data-stealing malware once you update them. More than 90 different Android apps available on Google Play have been found to contain malware, according to cloud cybersecurity firm Zscaler.

How do I remove hidden viruses from my Android? ›

  1. Step 1: Make sure Google Play Protect is turned on. Open the Google Play Store app . ...
  2. Step 2: Check for Android device & security updates. Get the latest Android updates available for you. ...
  3. Step 3: Remove untrusted apps. ...
  4. Step 4: Do a Security Checkup.

How do I scan my Android for Trojans? ›

Check for Android malware using Play Protect
  1. Open the Play Store on the Android device you want to scan.
  2. Tap on your profile in the upper-right corner.
  3. Tap on Play Protect.
  4. Tap Scan.
  5. Tap on the option to remove any detected malware.
Jan 5, 2023

How do I get rid of Trojan malware? ›

Follow these steps:
  1. Step 1: Disconnect internet. Before you start removing the Trojan, make sure that you disconnect from the internet. ...
  2. Step 2: Launch antivirus program. ...
  3. Step 3: Remove Trojan in Safe Mode. ...
  4. Step 4: Perform system recovery. ...
  5. Final option: Reinstall Windows 11.
Oct 27, 2023

Can a Trojan virus spy on you? ›

Trojans are used to spy on victims, steal data, infect other programs, and inflict other harm. Trojans are typically sent by scammers or hackers who use social engineering tactics, like the ones used in phishing attacks.

What virus can destroy Android phone? ›

Loapi malware is a new Android malware variant that is capable of causing permanent damage to Android smartphones. The new malware variant was recently discovered by researchers at Kaspersky Lab.

How do I check if my phone has a Trojan? ›

Antivirus detection: If you think you may have malware on your device, you can download an antivirus software or a complete mobile security app like F‑Secure Total that includes virus detection and removal. It's imperative to make sure the program you install is secure and trustworthy.

How to check for Trojans? ›

We recommend running a full virus scan on your computer if you think you have a trojan virus. That's the best way to tell if you have a Trojan virus. You can run the scan with your device's built-in antivirus or a third-party antivirus software.

How do I find hidden malicious apps on Android? ›

Check for apps you don't recognize. To do this, go to “Settings,” “Manage apps” or “Apps and notifications” and then “Downloaded apps” or “Installed apps.” Now look for apps that seem suspicious. Ask yourself whether you remember downloading them or whether you've ever used them. If not, delete them.

How can I find a hidden spyware on my Android? ›

Here's how to scan for spyware on your Android: Download and install Avast One. Run an antivirus scan (Smart Scan) to detect spyware or other forms of malware and viruses. Follow the instructions from the app to remove the spyware and any other threats that may be lurking.

What is the bank stealing malware on my Android phone? ›

Android users were particularly warned about Anatsa malware, also referred to as TeaBot. This malware can quickly obtain your banking information and use it to drain your accounts of money.

Can you fully remove a Trojan virus? ›

Can Trojan viruses be removed? Trojan viruses can be removed in various ways. If you know which software contains the malware, you can simply uninstall it. However, the most effective way to remove all traces of a Trojan virus is to install antivirus software capable of detecting and removing Trojans.

Is Trojan Remover free? ›

Download our free Trojan remover

AVG AntiVirus FREE scans and removes Trojans, then protects you from future attacks. Stay protected against malware and other threats with our 100% free security solution.

How to check for Trojans on Android? ›

Check for Android malware using Play Protect
  1. Open the Play Store on the Android device you want to scan.
  2. Tap on your profile in the upper-right corner.
  3. Tap on Play Protect.
  4. Tap Scan.
  5. Tap on the option to remove any detected malware.
Jan 5, 2023

How to clean your phone from virus for free on Android? ›

How to get rid of a virus from an Android phone
  1. Step 1: Check for Android device and security updates. ...
  2. Step 2: Scan your Android device with antivirus software. ...
  3. Step 3: Remove untrusted apps. ...
  4. Step 4: Try a different network or connection method. ...
  5. Step 5: Perform a security checkup on your Google account.
Jul 5, 2024

Top Articles
First Cash-Dispensing Bitcoin ATM Launched in Singapore - Asia Business News
How To Change Theme in Dreame Template
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Margart Wisoky

Last Updated:

Views: 5800

Rating: 4.8 / 5 (58 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Margart Wisoky

Birthday: 1993-05-13

Address: 2113 Abernathy Knoll, New Tamerafurt, CT 66893-2169

Phone: +25815234346805

Job: Central Developer

Hobby: Machining, Pottery, Rafting, Cosplaying, Jogging, Taekwondo, Scouting

Introduction: My name is Margart Wisoky, I am a gorgeous, shiny, successful, beautiful, adventurous, excited, pleasant person who loves writing and wants to share my knowledge and understanding with you.