Hackers paying $5K/month to gain access to 467 Android apps to steal banking info
ESET cybersecurity researchers have discovered a new version of 2021’s Android Banking Trojan ERMAC that is targeting 467 apps for stealing credentials and rob you of your hard-earned money.
The malware is being spread through fake websites. For instance, a fake version of Bolt Food’s site, which is a famous food delivery platform in Europe, has been created to target Polish users.
Once a user falls prey and downloads a fraudulent app, it asks for as many as 43 permissions, such as allowing it to read from external storage and letting it read text messages, and also asks the user to turn on the Accessibility Service. When that’s granted, it starts misusing services by enabling overlay activity and granting permissions.
The malware then sends a list of apps installed on the victim’s Android device to the Command and Control server. It then receives a response with the help of which it discreetly overlays legitimate apps and gains access to sensitive data and dangerous authorizations. India’s crypto app Unocoin was amongst the apps targeted this way.
The malware then stores an HTML phishing page on the device and when the victim uses the targeted genuine app, the phishing page is displayed instead to steal credentials, which are then sent back to the Command and Control server.
The hacker then uses the harvested information to steal cryptocurrency from the user’s account.
Banking applications targeted by ERMAC 2.0
Cyble notes that ERMAC is based on a well-known malware called Cerberus and cautions that the people behind ERMAC 2.0 will continue to make new versions with enhanced capabilities.
!function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function(){n.callMethod?n.callMethod.apply(n,arguments):n.queue.push(arguments)};if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version=’2.0′;n.queue=[];t=b.createElement(e);t.async=!0;t.src=v;s=b.getElementsByTagName(e)[0];s.parentNode.insertBefore(t,s)}(window,document,’script’,’https://connect.facebook.net/en_US/fbevents.js’);fbq(‘init’,’950812218873147′);fbq(‘track’,’PageView’);
For all the latest Technology News Click Here
For the latest news and updates, follow us on Google News.