This article warns users about Android banking trojans, a type of malware that steals online banking credentials and drains accounts.

Key points:

  • Prevalence: These trojans are disguised as legitimate apps and pose a serious threat to Android users, with Malwarebytes detecting over 88,500 in 2023 alone.
  • Deception: They often masquerade as everyday apps like fitness trackers or QR readers or productivity or photography tools, making them difficult to identify.
  • Permissions Requests: Once installed, they request permissions like accessing photos or files, but use them to steal login details.
  • Sneaky Tactics: Some even hide their app icon on the home screen and download additional malware later, bypassing Google Play’s security measures.
  • End Goal: Their ultimate aim is to steal your banking information and use it to make unauthorized money transfers.

The article emphasizes that vigilance is crucial, as these trojans are becoming increasingly sophisticated. It also references a recent Anatsa Trojan: https://www.techradar.com/pro/security/this-nasty-new-android-malware-can-easily-bypass-google-play-security-and-its-already-been-downloaded-thousands-of-times

  • GiooschiEnglish
    arrow-up
    28
    arrow-down
    1
    ·
    8 months ago
    edit-2
    8 months ago
    link
    fedilink

    Even after reading the key points it wasn’t clear “how” they manage to do that. The article is not much more detailed, but at least mentions them exploiting android’s accessibility services.

  • go $fsck yourselfEnglish
    arrow-up
    27
    arrow-down
    0
    ·
    8 months ago
    link
    fedilink

    This seems more like an ad for Malwarebytes’ premium service than an informational post.

    • OmgboomEnglish
      arrow-up
      6
      arrow-down
      0
      ·
      8 months ago
      link
      fedilink

      Fuck malwarebytes forever. I’ll never forgive them for not honoring my perpetual licenses that I purchased before they became subscription based all those years ago. I told them I was going to talk shit about them until the day I died, and I will keep that promise. I actually had to install malwarebytes the other day to try and fix a computer, malwarebytes itself is treading a fine line of being malware. It continually tells you you need to purchase a subscription, the app tries to get you to purchase a VPN through them, it gives random popups, I had no idea their service had gotten so bad.

      • go $fsck yourselfEnglish
        arrow-up
        2
        arrow-down
        0
        ·
        8 months ago
        link
        fedilink

        Yeah, I have not used Malwarebytes in years because it was obvious the quality has significantly declined.

  • LainTrainEnglish
    arrow-up
    9
    arrow-down
    1
    ·
    8 months ago
    link
    fedilink

    But I thought the data storage even if not encrypted (which afaik is standard as well) is now isolated for each app? And surely accessibility permissions are a separate category you have to grant also?

    • Squire1039OPEnglish
      arrow-up
      3
      arrow-down
      0
      ·
      8 months ago
      link
      fedilink

      Yeah, the app data are separated and inaccessible, unless specified by the developer. Accessibility service is a separate permission, and should almost never be asked or granted, where as file/photo accesses are more common.

  • mindlightEnglish
    arrow-up
    6
    arrow-down
    0
    ·
    8 months ago
    link
    fedilink

    Wait what Who can login to the internet bank with just a user/password?

    We’ve had MFA requirement here in Sweden since the early 00’s

    • doppelgangmemberEnglish
      arrow-up
      4
      arrow-down
      0
      ·
      8 months ago
      edit-2
      8 months ago
      link
      fedilink

      mean while 23andme gaslighting customers

      👀