IT experts from the cybersecurity company Fox-IT locate the already well-known banking Trojan “ Sharkbot ” behind two supposedly secure Android apps in the Google Play Store

In order to pass the automatic security checks that every app must undergo before it is released for the Play Store, the apps did not contain any malicious code at this point. This was only installed on the end devices after the installation, hidden in an update.

Banking Trojan steals login data from online banking apps

If the Trojan was successfully installed via the update, the attackers can access the login data from online banking apps via the cookies used. This is how the attackers gain access to the bank account.

Sharkbot was first discovered in October 2021 and has evolved significantly since it first appeared in an antivirus app in February this year. While the malware back then required consent to certain permissions in order to install itself on the end devices, now the detour via cookies is sufficient to obtain the desired data.

60,000 downloads

The antivirus app and the data cleaning application were downloaded a total of almost 60,000 times. Customers from Spain, Australia, Poland, Germany , the USA and Austria . Fortunately, so far there have only been a few cases in which such an attack has been successful.

Uninstall immediately

If one of the applications mentioned has found its way onto your smartphone, you should uninstall it immediately and then scan the device with trustworthy antivirus software. listed HERE how you can detect malware and remove it from your PC, laptop, tablet or smartphone.

You might also be interested in : “ Caution: Cleaner apps for Android bring malware

Source : Futurezone

Notes:
1) This content reflects the current state of affairs at the time of publication. The reproduction of individual images, screenshots, embeds or video sequences serves to discuss the topic. 2) Individual contributions were created through the use of machine assistance and were carefully checked by the Mimikama editorial team before publication. ( Reason )