Money-stealing apps hit 300,000 Android phones - Oh no not again!

3 years ago
110

Money-stealing apps hit 300,000 Android phones - what to do and who's effected
Apps seem fine at first, but load malware over time
More than 300,000 Android users have installed rogue apps from the Google Play store that eventually develop into money-stealing banking Trojans through a series of incremental updates.
All these malicious apps have been booted out of the Google Play store, but at least some are probably still available in "off-road" app stores. You'll want to make sure that you remove them if you have any of these apps installed.
You may have installed one or more of these apps that have been removed from the Google Play store
The full list of these malicious apps is here, with their screen names followed by their Android package names:

CryptoTracker — cryptolistapp.app.com.cryptotracker
Gym and Fitness Trainer — com.gym.trainer.jeux
Master Scanner Live — com.multifuction.combine.qr
PDF Document Scanner — com.docscanverifier.mobile
PDF Document Scanner Free — com.doscanner.mobile
PDF Document Scanner - Scan to PDF — com.xaviermuches.docscannerpro2
Protection Guard — com.protectionguard.app
QR CreatorScanner — com.ready.qrscanner.mix
QR Scanner — com.qr.barqr.scangen
QR Scanner 2021 — com.qr.code.generate
Two Factor Authenticator — com.flowdivison
If you have these on your andriod drive uninstall them now!
"[Threat] actors are focusing on loaders with a reduced malicious footprint in Google Play, considerably increasing the difficulties in detecting them with automation and machine learning techniques," explained ThreatFabric.
The apps are mostly QR-code or PDF scanners, and they work as promised. They were cleared by Google Play as safe because the malware isn't added until the apps have been running on the devices for a while.

The malware tries to steal login credentials for banking, cryptocurrency and payment apps, plus some email and general-purpose apps. Targeted countries include Australia, the U.K. and the U.S., plus many countries in Europe and Southeast Asia.

Targeted financial apps include those from Bank of America, Barclays, Binance, Capital One, Cash App, Chase, Citibank, Citizens Bank, Coinbase, Credit Suisse, HSBC, Lloyds, NatWest, PNC Bank, Royal Bank of Scotland, TD Bank, Wells Fargo and Zelle, plus dozens of others. Other targeted apps include Gmail, Google Play, Microsoft Outlook, Netflix and Yahoo Mail.
Sources of info and Credts:
https://www.tomsguide.com/news/stealth-banking-trojans-300000-phones
https://www.mediarunsearch.co.uk/delete-it-now-android-apps-steal-users-money-see-the-list-technique/
https://www.businessinsider.in/tech/apps/news/android-apps-that-steal-banking-information-were-dow
https://www.phonearena.com/news/8-android-apps-steal-data-and-money_id133026
https://www.tweaktown.com/news/35583/malicious-apps-in-google-play-store-increased-almost-400-percent/index.html
Home News Security
Money-stealing apps hit 300,000 Android phones — what to do
By Paul Wagenseil

Thanks for watching
Please help us hit the 1000 subscriber count this month by subscribing

Video by Tima Miroshnichenko from Pexels - 3d
Video by Carlos Arribas from Pexels phone
Video by Andre Moura from Pexels world
Video by cottonbro from Pexels computer
Music from Uppbeat (free for Creators!):
https://uppbeat.io/t/atm/follow-your-heart
License code: OZTGD3TWBVK8BWGI
Music from Uppbeat (free for Creators!):
https://uppbeat.io/t/atm/follow-your-heart
License code: WA2CYGEMUNGDWYC7

Loading comments...