'Dangerous' banking malware targets Android

Password. (Duncan Alfreds, Fin24)
Password. (Duncan Alfreds, Fin24)

Cape Town – Android mobile banking customers have to be wary of new malicious software capable of attacking online financial services, warns a security company.

Kaspersky Lab has warned that Acecard malware is able to bypass Google’s Play store security controls and trick users into downloading it.

“Mobile devices were usually infected after downloading a malicious application masquerading as a legitimate one. Acecard versions are typically distributed as Flash Player or PornoVideo, although other names are sometimes used in a bid to imitate useful and popular software,” Kaspersky said in a statement.

While the Trojan first made its appearance in 2014, Kaspersky noted a spike in late 2015 with 6 000 attacks as cyber authors developed up to 10 new versions of the malware.

It works by overlaying applications like Facebook, Gmail, WhatsApp and Skype with fake windows in order to steal login information and account details.

Creators

READ: Cyber crooks stalk victims on Valentine's Day

“A distinctive feature of this malware is that it’s capable of overlaying more than 30 banking and payment systems as well as social media, instant messaging and other apps,” said Roman Unuchek senior malware analyst at Kaspersky Lab US.

“The combination of Acecard’s capabilities and methods of propagation make this mobile banker one of the most dangerous threats to users today,” he warned.

Kaspersky believes that the code of the malware is similar enough to malware like TOR Trojan for Android Backdoor.AndroidOS.Torec.a and ransomware Trojan-Ransom.AndroidOS.Pletor.a that it indicates similar authorship.

“This cyber criminal group uses virtually every available method to propagate the banking Trojan Acecard. It can be distributed under the guise of another programme, via official app stores, or via other Trojans,” Unuchek said.

Kaspersky Lab advised Android users to avoid suspicious web pages and download links.


- Follow Duncan on Twitter

ZAR/USD
16.94
(+0.04)
ZAR/GBP
21.09
(+0.34)
ZAR/EUR
19.02
(+0.29)
ZAR/AUD
11.75
(-0.02)
ZAR/JPY
0.16
(+0.22)
Gold
1775.55
(+0.03)
Silver
18.00
(+0.48)
Platinum
813.16
(+0.82)
Brent Crude
42.92
(+2.64)
Palladium
1899.18
(+0.66)
All Share
54713.26
(+0.18)
Top 40
50405.82
(+0.19)
Financial 15
10189.16
(-0.25)
Industrial 25
76817.24
(+0.87)
Resource 10
50451.26
(-0.62)
All JSE data delayed by at least 15 minutes morningstar logo
Company Snapshot
Voting Booth
Please select an option Oops! Something went wrong, please try again later.
Results
I'm not really directly affected
18% - 1562 votes
I am taking a hit, but should be able to recover in the next year
23% - 2025 votes
My finances have been devastated
34% - 3040 votes
It's still too early to know what the full effect will be
25% - 2201 votes
Vote