Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Important Resources & Information Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Users Get Tricked Into Falsely Updating Google Services
Facebook   X   LinkedIn   Email

Users Get Tricked Into Falsely Updating Google Services

May 18, 2025

The TrickMo Android banking trojan has re-emerged in a new form, disguised as a fake Google Chrome app for Android. Once installed, this malicious app prompts users to update Google Play Services, tricking them into downloading TrickMo under the guise of "Google Services." By doing so, it gains access to critical permissions, including those for the device's accessibility settings, which it then exploits to perform various malicious activities.

This new iteration of TrickMo is particularly dangerous because it can intercept SMS messages, steal one-time passwords (OTPs), record screen activity, and perform HTML overlay attacks. These overlay attacks mimic legitimate banking and crypto login pages, tricking users into providing sensitive credentials. The trojan also enables remote control of the device, allowing attackers to execute unauthorized actions without the user's knowledge.

Furthermore, TrickMo's advanced capabilities allow it to bypass traditional security, such as a password. It uses malformed ZIP files and employs techniques to evade detection, making it even more challenging to identify the threat.

To avoid becoming a victim, Android users should download apps only from the official Google Play Store. In other words, don’t sideload apps or get them from third party sources. Also, regularly updating devices and avoiding granting unnecessary permissions is crucial to keeping secure, and is appropriate for all users. If your app doesn’t need access to a service, don’t enable it. Try using it with the least number of permissions and see if it works. It’s a very rare time that any app needs access to the accessibility settings or needs developer access. Activating Google Play Protect and staying vigilant against suspicious updates or popups are also key steps to protect against such malware.


Can Hackers Take A Bite Out Of  Your Mobile Pay Solution?

Mobile Security

Can Hackers Take A Bite Out Of Your Mobile Pay Solution?

With the many digital payment options available today, finding the most secure providers can be a challenge. The popularity of digital wallets has grown over time and writing checks and even using plastic cards for payments are quickly becoming the dinosaurs of our non-digital past. Many users now own mobile wallets and pay for goods and services. And using Apple Pay, Google Pay or another service for those transactions may offer peace of mind knowing your payment data is safe and out of the reach of hackers. READ FULL STORY

The Most Hacked Apps To Get To Your Details

Mobile Security

The Most Hacked Apps To Get To Your Details

We share a lot these days. Some might even say we spout personal details like a water from a fire hydrant, especially when it comes to social media. For hackers, that means they have us all right where they want us. Researchers at TechShielder put in some work and found that there are a number of apps available to us that actually have been repeatedly compromised and share our personal information with plenty of others that we may not want to have our information. READ FULL STORY

One Billion+ Android App Downloads Are Hiding Banking Trojans. Is One Yours?

Mobile Security

One Billion+ Android App Downloads Are Hiding Banking Trojans. Is One Yours?

With over one billion trojan banking malware downloads from 639 apps on Google Play Store, it’s time for mobile Android users to pay attention. After all, it’s ultimately the victims who end up paying the price for Google not finding the malware before making it available on their Play Store. Despite Google’s recently improved efforts to keep malware out of their App Store, like introducing Play Protect, it appears there’s a lot more work to be done. READ FULL STORY

More Pop-Up Ads? Yes Please! Said No One. Ever!

Your Security

More Pop-Up Ads? Yes Please! Said No One. Ever!

Those intrusive pop-up ads that slow down our browsers and bounce the content we want to read are by most accounts, insufferable. Knowing that, developers have created ad blocker extensions to help with this annoying and potentially harmful web surfing issue. One self-proclaimed ad-blocking extension, AllBlock Chromium, however, is doing the exact opposite of what it says it does and those behind it are making profits off that broken promise. READ FULL STORY

BlackCat Brings Bad Luck Using Google Ads

Scams & Phishing

BlackCat Brings Bad Luck Using Google Ads

Trend Micro researchers recently identified that a notorious ransomware group is using various malvertising tricks within Google Ads to distribute fake WinSCP installers. They are using Targeted Attack Detection (TAD) service. What is that, you say? This means that if you click on an infected ad that you see on your webpage, your network could get a bad case of cat scratch fever. Threat actors are taking advantage of Google Ads to launch malvertising campaigns. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...