Android banking Trojan may target Indian banks' mobile apps: Quick Heal

IANS  |  Pune 

Global IT security firm on Thursday announced it has spotted an Trojan that imitates more than 232 mobile apps, including those offered by Indian like SBI, HDFC, ICICI, and Axis, among others.

According to the researchers, the malware known as "A2f8a" is being distributed through a fake Player app on third-party stores.

After downloading the app, it keeps checking for the installed apps on the victim's device and particularly looks for the 232 and cryptocurrency apps.

Once any of the targeted apps is found on the device, the app shows fake notifications disguised as coming from the targeted app and asks users to log in with their credentials and ultimately tricks them by stealing their login ID and password.

"Users are advised to avoid downloading apps from third party app stores or links provided in SMSs and emails to keep their credentials safe," Sanjay Katkar, Joint Managing Director and Chief Technology Officer, Quick Heal Technologies Limited, said in a statement.

"It is also strongly advised to keep device OS and mobile security app up-to-date," he added.

In the background, the app carries out malicious tasks -- it keeps checking the installed app on the victim's device and particularly looks for 232 apps (and some cryptocurrency apps).

If any one of the targeted apps is found on the infected device, the app shows a fake notification on behalf of the targeted app. If the user clicks on the notification, they are shown a fake login screen which enables stealing the user's confidential info like net login ID and password.

"Install a reliable mobile security app that can detect and block fake and malicious apps before they can infect your device," Quick Heal said.

--IANS

na/dg

(This story has not been edited by Business Standard staff and is auto-generated from a syndicated feed.)

First Published: Thu, January 04 2018. 19:02 IST