A new Android banking malware was discovered by security researchers that targets Brazil’s Itaú Unibanco by using lookalike Google Play Store pages to conduct fraudulent financial transactions on victim devices without their knowledge.
According to Cyble researchers, this application has a similar icon and name that could trick users into thinking it is a legitimate app related to Itaú Unibanco. The threat actor has created a fake Google Play Store page and hosted the malware that targets Itaú Unibanco on it under the name ‘sincronizador.apk.'”
The fake URL impersonates the official Android app marketplace and also hosts the malware-laced Itaú Unibanco application, in addition to claiming that the app downloaded 1,895,897 times.
The users who install and launch the imposter app from the supposed Google Play Store page are prompted to enable accessibility services as well as other intrusive permissions that allow the malware to access notifications, retrieve window content, and perform tap and swipe gestures.
The main aim of the trojan is to perform fraudulent financial transactions on the legitimate Itaú Unibanco application by tampering with the user’s input fields.
Google has begun imposing new limitations to restrict the use of such permissions that allow apps to capture sensitive information from Android devices.
The researchers stated that threat Actors constantly adapt their methods to avoid detection and find new ways to target users through increasingly sophisticated techniques. Such malicious applications often masquerade as legitimate applications to trick users into installing them.
They recommend that users should install applications only after verifying their authenticity and install them exclusively from the official Google Play Store and other trusted portals to avoid such attacks.














Comments