FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

We’re A Little Worried About this Android Banking Malware, and Here’s Why

Grace NotobyGrace Noto
November 7, 2016
in Risk & Security
Reading Time: 3 mins read
0
Share on Facebook

canstockphoto4048920It’s a rough year to be an Android fan: a new banking Trojan has infected over 200,000 Android devices over the last month, by influencing or pushing users to enter their online or banking credentials into a screen overlaid onto the open app.

The Android Trojan is targeting a collection of over 90 banks and other financial services  — including JP Morgan Chase, Credit Karma, Bank of America, Deutsche Bank, and American Express — in the U.S. and throughout countries in Europe,  including Turkey and Austria.

“Certain [financial] apps leverage SMS to send fraud alerts,” says Tim Condello, technical account manager for information security company RedOwl. “With [the malware’s] ability to intercept calls and texts it could impede the user’s ability to know that there is fraud on that account.”

Intercepting SMS and calls is a kind of way to crack two-factor authentication without technically cracking it, according to Condello — the malware sits inside SMS traffic and requires administrator rights to work, so technically two-factor authentication hasn’t quite been shoved wide open, just…skirted.

The two-factor method of authentication is, of course, employed by a multitude of apps, but is a favorite among banks and other money services one might use on mobile — which is being utilized more and more people across the globe, when conducting individual banking.

“Many banks are using [two-factor] to authenticate who the user is,” says Don Duncan, security engineer at behavioral biometrics company NuData Security; who added that for banks, stopping these types of data breaches is an integral part of building a relationship of trust with mobile users.

“The question [for us] becomes, how can we help the banks allow users to safely bank [on mobile]?” says Duncan. “The nice thing about behavioral biometrics is that it can occur without being in the user’s face.”

The malware works the way most Trojans work—by overlaying a branded screen onto the app a user opens, whereby the user is asked to input their credit card information or banking credentials.

Displaying a fake login screen over a banking app is definitely a concern, but the good news is that it’s very easy to see if your Android device is one of the horde: the Trojan will also display a screen asking for credentials over social media apps like Facebook or Twitter, which is a pretty clear-cut indicator that something is off with your phone.

Even though this Trojan has infected more than 200,000 individual devices in half a dozen countries, and has targeted 90+ banks, the other intriguing thing about this malware is the fact that it actually requires a very specific set of circumstances to occur before it, well, works.

First, the user can’t have any time of anti-virus software on their device, because the malware will be picked up immediately. Next, the malware has also been shuffled out of the Google Play store, so downloading it requires a user to do what’s called “sideloading”—essentially downloading an app outside of the Play store.

Moving down through a checklist of factors, at the end the malware can only work with administrator rights, granted by the user.

As it’s easy to tell if your device is infected — at least if a credit card information screen is showing up over Facebook — it’s equally easy to disarm the Trojan: simply turn off administrator rights on settings, and then uninstall the Trojan like you would anything else.

So far no version of the malware appears to have migrated over to Apple products.

Tags: AndroidcybersecurityMobile bankingNuData Security
Previous Post

Riskalyze Pulls in $20 Million Series A, Has No Plans To Go Public

Next Post

Innovation Spotlight: USAA’s Zachary Gipson, Mastercard’s Garry Lyons

Related Posts

humans and AI work together to pinpoint risk and suspicious activity
Risk & Security

Retaining the human component as AI combats fraud

July 28, 2026
a digital grid superimposed over a globe
Risk & Security

AI finding twice as many cyber flaws in 2026 as it did in 2025

July 27, 2026
uipath
Risk & Security

Inetco launches agentic AI fraud investigation tool

July 24, 2026
Next Post

Innovation Spotlight: USAA's Zachary Gipson, Mastercard's Garry Lyons

Please login to join discussion

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account