10 Most Prolific Banking Trojans Targeting Hundreds of Financial Apps with Over a Billion Users
10 of the most prolific mobile banking trojans have set their eyes on 639 financial applications that are available on the Google Play Store and have been cumulatively downloaded over 1.01 billion times.
“TeaBot is targeting 410 of the 639 applications tracked,” mobile security company Zimperium said in a new analysis of Android threats during the first half of 2022. “Octo targets 324 of the 639 applications tracked and is the only one targeting popular, non-financial applications for credential theft.”
In addition, the rogue apps are equipped with the ability to evade detection by often hiding their icons from the home screen and are known to log keystrokes, capture clipboard data, and abuse accessibility services permissions to pursue their objectives such as credential theft.
This involves the use of overlay attacks, pointing a victim to a fake banking login page that’s displayed atop legitimate financial apps and can be used to steal the credentials entered. Consequences of such attacks can range from data theft and financial fraud to regulatory fines and loss of customer trust.