FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

We’re A Little Worried About this Android Banking Malware, and Here’s Why

Grace NotobyGrace Noto
November 7, 2016
in Risk & Security
Reading Time: 3 mins read
0
Share on Facebook

canstockphoto4048920It’s a rough year to be an Android fan: a new banking Trojan has infected over 200,000 Android devices over the last month, by influencing or pushing users to enter their online or banking credentials into a screen overlaid onto the open app.

The Android Trojan is targeting a collection of over 90 banks and other financial services  — including JP Morgan Chase, Credit Karma, Bank of America, Deutsche Bank, and American Express — in the U.S. and throughout countries in Europe,  including Turkey and Austria.

“Certain [financial] apps leverage SMS to send fraud alerts,” says Tim Condello, technical account manager for information security company RedOwl. “With [the malware’s] ability to intercept calls and texts it could impede the user’s ability to know that there is fraud on that account.”

Intercepting SMS and calls is a kind of way to crack two-factor authentication without technically cracking it, according to Condello — the malware sits inside SMS traffic and requires administrator rights to work, so technically two-factor authentication hasn’t quite been shoved wide open, just…skirted.

The two-factor method of authentication is, of course, employed by a multitude of apps, but is a favorite among banks and other money services one might use on mobile — which is being utilized more and more people across the globe, when conducting individual banking.

“Many banks are using [two-factor] to authenticate who the user is,” says Don Duncan, security engineer at behavioral biometrics company NuData Security; who added that for banks, stopping these types of data breaches is an integral part of building a relationship of trust with mobile users.

“The question [for us] becomes, how can we help the banks allow users to safely bank [on mobile]?” says Duncan. “The nice thing about behavioral biometrics is that it can occur without being in the user’s face.”

The malware works the way most Trojans work—by overlaying a branded screen onto the app a user opens, whereby the user is asked to input their credit card information or banking credentials.

Displaying a fake login screen over a banking app is definitely a concern, but the good news is that it’s very easy to see if your Android device is one of the horde: the Trojan will also display a screen asking for credentials over social media apps like Facebook or Twitter, which is a pretty clear-cut indicator that something is off with your phone.

Even though this Trojan has infected more than 200,000 individual devices in half a dozen countries, and has targeted 90+ banks, the other intriguing thing about this malware is the fact that it actually requires a very specific set of circumstances to occur before it, well, works.

First, the user can’t have any time of anti-virus software on their device, because the malware will be picked up immediately. Next, the malware has also been shuffled out of the Google Play store, so downloading it requires a user to do what’s called “sideloading”—essentially downloading an app outside of the Play store.

Moving down through a checklist of factors, at the end the malware can only work with administrator rights, granted by the user.

As it’s easy to tell if your device is infected — at least if a credit card information screen is showing up over Facebook — it’s equally easy to disarm the Trojan: simply turn off administrator rights on settings, and then uninstall the Trojan like you would anything else.

So far no version of the malware appears to have migrated over to Apple products.

Tags: AndroidcybersecurityMobile bankingNuData Security
Previous Post

Riskalyze Pulls in $20 Million Series A, Has No Plans To Go Public

Next Post

Innovation Spotlight: USAA’s Zachary Gipson, Mastercard’s Garry Lyons

Related Posts

(Courtesy/Bloomberg)
Risk & Security

Anthropic releases Mythos 5 and Fable 5

June 9, 2026
Image by Pixabay
Risk & Security

Fenergo AI agents save 18K hours of compliance work annually

June 5, 2026
Courtesy: Nvidia website
Risk & Security

Nvidia launches AI-driven fraud detection tool

June 2, 2026
Next Post

Innovation Spotlight: USAA's Zachary Gipson, Mastercard's Garry Lyons

Please login to join discussion

Stay Informed with Our Newsletters

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

Hiding in Plain Sight: How to Use Data to Spot Consumer Accounts Being Used by Small Businesses

November 10, 2025

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Create a free account, or log in.

Gain access to read this article, plus limited free content.

Yes! I would like to receive new content and updates.

Upgrade your subscription

Get full access to all content.
Upgrade Now
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account