HomeSecurityCheat Tool for Android Games Delivers Dangerous Banking Trojan

Cheat Tool for Android Games Delivers Dangerous Banking Trojan

Security researchers from the Russian company Dr.Web have discovered a new banking trojan called Android.BankBot, hidden inside a game cheat tool for Android users.

Google didn't name its app store "Play" Store for nothing, as it knew very well that games would take up most of our time while we were on our devices, and it was right.

Cheat Tool for Android Games Delivers Dangerous Banking Trojan

The Play Store is now home to millions of games, from the simplest word puzzles to full-fledged sports simulators, like EA Madden Mobile.

As with desktops, not all users are inclined to play these games, and some feel the need to "steal" to get to the top of a track's leaderboard or when playing with friends.

The world of game cheating tools doesn't stop with desktops, and there are many such tools available for Android devices. Dr.Web warn users not to fall victim to their pride and narcissism and stay away from these tools.

The company bases its advice on a recent discovery of a cheating app for Android games with the simple name HACK.

Scammers distribute this app from third-party stores and immediately request administrator privileges from users who install it.

Once they are given, you probably know what is happening. HACK hides its icon from the home screen, remotely collects data from the infected device, and initiates communication with a central command server.

From there, the scammers begin harvesting login credentials for the user's banking applications and then give instructions to exfiltrate funds from the exposed account.

To avoid two-factor authentication procedures, Android.BankBot can intercept and send USSD requests, SMS, and even call forwarding.

However, the app is not as dangerous as an Android banking trojan discovered by Trend Micro and called Fanta SDK. This trojan, if detected by the user, locks the device with a random PIN in order to empty the user's bank account.

Trend Micro said it found the Fanta SDK on the same servers used to distribute other Android banking trojans, such as ZBot. Additionally, Dr.Web revealed that the same Web server that distributed the HACK application also spreads ZBot.

Below is a screenshot of the required privileges of the malicious application and then the application requesting administrator rights from the user:

printscreen for cheat tool

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS