• IP addresses are NOT logged in this forum so there's no point asking. Please note that this forum is full of homophobes, racists, lunatics, schizophrenics & absolute nut jobs with a smattering of geniuses, Chinese chauvinists, Moderate Muslims and last but not least a couple of "know-it-alls" constantly sprouting their dubious wisdom. If you believe that content generated by unsavory characters might cause you offense PLEASE LEAVE NOW! Sammyboy Admin and Staff are not responsible for your hurt feelings should you choose to read any of the content here.

    The OTHER forum is HERE so please stop asking.

Banking Malware Masked as PayPal App Targeting Android Users

KimKaphwan

Alfrescian
Loyal
Joined
Nov 3, 2013
Messages
52
Points
0

Banking Malware Masked as PayPal App Targeting Android Users

By Carolina on October 7, 2015

android-banking-malware-masked-as-paypal-app-3.jpg


Image Source: Flickr

Hackers are targeting users with fake PayPal app update email which actually comes with an embedded link of an Android banking malware.

Recently, an email circulation has been let loose by hackers. This email looks quite official in design and content, asking the recipient to update their Android PayPal app.

If the users click on the given link, a download is triggered. This download is a mobile online banking Trojan that has been detected by Trend Micro as AndroidOS_Marchcaban.HBT.

Trend Micro says in a post that the language used in the email suggests that people living in Germany are their main target. It also reports that this email has been sent over 14,000 times in variations.

android-banking-malware-masked-as-paypal-app.png


Screenshot of the email sent by the hackers / Image Source: Trend Micro

After a user installs this application, a request to act as system administrator appears on the screen along with a request relating to other privileges.

android-banking-malware-masked-as-paypal-app-3-side.png


Permissions request from the malware app

“Once the malware detects the real PayPal app is running, it will put up a fake UI on top of the real one, effectively hijacking the session and stealing the user’s PayPal credentials,” the post said. Furthermore, it has been said that this code is also employed to target various banking-related apps like Commerzbank.

Once the user installs the so-called update, the malware checks for the original PayPal app. Once detected, the malware puts up its own UI on the top of the original PayPal app which lets the fake app steal your PayPal login data.


 
Back
Top