Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
One Billion+ Android App Downloads Are Hiding Banking Trojans. Is One Yours?
Facebook   X   LinkedIn   Email

One Billion+ Android App Downloads Are Hiding Banking Trojans. Is One Yours?

October 14, 2024

With over one billion trojan banking malware downloads from 639 apps on Google Play Store, it’s time for mobile Android users to pay attention. After all, it’s ultimately the victims who end up paying the price for Google not finding the malware before making it available on their Play Store.

According to a report by BleepingComputer, based on findings by Zimperium mobile device security, the top ten most prolific and dangerous mobile banking trojans infiltrated 639 gaming and other benign apps on Google Play. Many who downloaded these apps may still be in the dark, but take some comfort knowing you’re now aware.

Despite Google’s recently improved efforts to keep malware out of their App Store, like introducing Play Protect, it appears there’s a lot more work to be done. At the same time, hackers have been improving their own efforts infecting Android apps and bypassing security checks. Research by Panda Security suggests Android devices are infected by malware 47 times more often than with iOS.

Top Apps Targeted by Banking Trojans

BleepingComputer reports U.S. users are the most threatened globally. They find 121 of the 639 apps are made to specifically target American users, with the UK next with 55 apps. It may not come as a surprise since three out of four U.S. banking customers rely on these apps for their daily financial transactions. Below are the top apps downloaded from Google Play that are most vulnerable to banking malware.

  • PhonePe, popular in India, had the most downloads with 100 million
  • Binance, a popular cryptocurrency exchange app had 50 million downloads
  • Cash App, a mobile payment service for the U.S. and UK also had 50 million downloads
  • BBVA, a global banking portal, is targeted by seven out of ten of the most prolific banking trojans. The app has tens of millions of downloads

Banking Trojans Targeting the Most Apps

  • TeaBot targeted 410 of 639 apps, while ExoBot targeted 324 apps
  • BianLian
  • Cabassous
  • Coper
  • EventBot
  • Exobot

Doing your homework before downloading banking apps can save you a lot of headaches. Read app reviews, make sure your apps are updated, and don’t download (called “sideloading”) apps from third-party stores. It’s an app jungle out there, so be prepared.


BOLO for These Most Dangerous Email Attachments

Scams & Phishing

BOLO for These Most Dangerous Email Attachments

Keeping a lookout for suspicious emails has become a daily consequence of our cyber lives. Phishing emails are notorious for having malicious attachments and opening them is a sure way to compromise your device and its data. These attachments are full of malware, ready and waiting to infect your system with a simple click. Make no mistake, any attachment in a questionable email can be dangerous. However, researchers at F-Secure found that some of this year’s biggest email spam campaigns used particular types of malicious attachments more than others. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...