Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
BOLO Android Banking Apps — New Malware Evades Detection
Facebook   X   LinkedIn   Email

BOLO Android Banking Apps — New Malware Evades Detection

February 1, 2024

A new malware targeting Android banking apps is making its way around the globe, and the U.S. may be in its path. Called FjordPhantom, this tricky malware is infecting banking apps with help from sophisticated tricks for flying under the radar. This banking trojan's clever mix of phishing emails combined with social engineering TOAD attacks helps this malware get what it's after...your banking credentials and your money. Don’t know what a TOAD attack is. Well, in short, it’s not the amphibious kind. We’ll get to it shortly.

FjordPhantom is actively attacking banking app users in Thailand, Indonesia, Malaysia, Singapore, and other Southeast Asian countries, with one victim losing $280,000. Experts see signs of FjordPhantom actively developing and growing far beyond its current geo-locations.

Bank Fraud On-The-Go

Promon analysts first discovered FjordPhantom malware spreading through emails, messaging apps, and SMS text messaging. That's when socially engineered telephone-oriented-attack delivery (TOAD) strikes, often in the form of calls from a bogus bank customer service line. Step-by-step, a victim is swayed into downloading a banking app with authentic features that unknowingly include FjordPhantom's malware.

Android banking apps are vulnerable to FjordPhantom because the malware is written in a modular way. Depending on what banking app gets caught up in the malware, the apps get attacked. In the end, FjordPhantom hijacks PII, steals credentials, and controls banking transactions.

Undetected Ways

In some cases, FjordPhantom keeps victims in the dark by closing screen warning messages about the intrusion. Since the malware doesn't alter the banking app, code tampering doesn't get detected. Although Google says their Play Protect works to scan and identify malicious apps before they're installed, this malware gets around on a device by making Google Play Services look unavailable.

In the widening world of Android banking malware, FjordPhantom is making a name by hiding itself, so BOLO! Here is how you can avoid it:

  • Don’t sideload apps. These usually don’t get tested for security issues as thoroughly as the ones in the official app stores or may not get scanned for them at all.
  • Keep your devices up to date with current antimalware software and make sure you apply all patches to software and update your mobile devices when one is available.
  • Keep the peepers open for targeted phishing email messages and texts. No email or text is so urgent you can’t take a minute to make sure they’re safe.
  • Avoid clicking links and attachments, no matter how you receive them. Remember that sometimes they even arrive in voice to text voicemail messages!
  • Always verify and re-verify your financial account links before entering any sensitive information.

Can Hackers Take A Bite Out Of  Your Mobile Pay Solution?

Mobile Security

Can Hackers Take A Bite Out Of Your Mobile Pay Solution?

With the many digital payment options available today, finding the most secure providers can be a challenge. The popularity of digital wallets has grown over time and writing checks and even using plastic cards for payments are quickly becoming the dinosaurs of our non-digital past. Many users now own mobile wallets and pay for goods and services. And using Apple Pay, Google Pay or another service for those transactions may offer peace of mind knowing your payment data is safe and out of the reach of hackers. READ FULL STORY

Is Sideloading Worth The Risk Of Downloading Malware?

Your Security

Is Sideloading Worth The Risk Of Downloading Malware?

It’s been well-known that sideloading apps is a risky proposition. Just ask the 20 million Aptoide users who recently learned their personally identifiable information (PII) was posted online by a hacker. Aptoide, a popular third-party app “discovery platform” had its database hacked earlier this month. The cybercriminal behind the hack claims that in addition to the 20 million exposed data files, there’s an additional 19 million files in their possession. Whether that’s true or not remains a mystery for now, but the Aptoide incident shows (in a huge way) why app sideloading is risky at best and is not recommended by security professionals. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...