Slashdot Mirror


Android Banking Trojan Masquerades As Flash Player, Circumvents 2FA

A newly found Android trojan is targeting customers of large banks in Australia, New Zealand and Turkey. The banking malware, flagged as Android/Spy.Agent.SI by ESET security firm, disguises itself as Flash Player and spreads via unofficial app stores. It can steal login credentials of users from 20 mobile banking apps, and can also mimic login screens of popular services such as PayPal, eBay, Skype, WhatsApp and several Google services. The Android trojan is able to intercept SMS communications, which in turn, allows it to circumvent the two-factor authentication.

5 of 51 comments (clear)

  1. Re:Intercept SMS? by Chrisq · · Score: 3, Insightful

    This is one of my pet hates about android (and I'm generally a fan). A lot of apps ask for that permission but just for registration. Up until the latest version (and still on one of my phones) you had to accept this permission to register but then had no way to revoke it afterwards, so you had to hope for the lifetime of the app that it wasn't compromised and wouldn't start messaging premium-rate SMS services or forwarding your message.

  2. Re:More Complete Pwnage by Arnold+Reinhold · · Score: 2

    Scroll down two stories to read the usual Slashdot sneering about Apple products.

  3. No Flash by DrYak · · Score: 3, Funny

    Actually *NOT* playing flash (even more so flash ads) would be a *positive* feature.
    Almost redeeming its trojan-ness.

    --
    "Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
  4. Re:Intercept SMS? by castionsosa · · Score: 2

    That is only if the app developer allows that in the manifest. Otherwise, the app falls back to the all or nothing permission model.

    The best solution is XPrivacy/XPosed, but IIRC, that hasn't worked since Android 5 came out. Second best solution is either CyanogenMod, or if you can read Chinese and choose to trust the app, LBE Privacy Master.

  5. That's funny by JustAnotherOldGuy · · Score: 2

    "The banking malware ... disguises itself as Flash Player..."

    That's funny, usually it's the other way around.

    --
    Just cruising through this digital world at 33 1/3 rpm...