Uneducated and perhaps naive Android users appear to be the target of an Android banking trojan (Acecard) that asks its victims to send a selfie holding their police ID.
The trojan's name is Acecard and it is considered one of the most dangerous and intrusive Android banking trojans known today, according to a Kaspersky analysis from last February.
In a previous version, the Acecard trojan was hidden inside a Black Jack game distributed through the official Google Play Store. The latest version of the malware, according to McAfee security researchers, can be hidden inside all kinds of applications that use Adobe Flash Player, in pornography or in video codecs.
All of these apps are distributed outside of the Play Store and are known for constantly asking for the victim's permission until they get what they want, namely administrator rights.
Once this step is achieved, the trojan hides until the user opens a specific app. McAfee researchers found that when the user opens the Google Play app, the trojan uses a social engineering trap.
First, it asks the user for their credit card number. Then, in different pop-ups, it asks the user for their card details, such as name and expiration date, but it also asks for their real identity details.
After that, the trojan gives its victim new instructions requiring them to take front and back photos of their ID. In the third stage, the trojan asks the user to hold the ID in their hand, under their face, and take a selfie.
“This is very useful for a cybercriminal who wants to confirm the victim’s identity and gain access not only to bank accounts, but perhaps even to social networks,” says McAfee’s Carlos Castillo.
It should be mentioned that in addition to Google Play, this version of Acecard also collects access credentials from the following services: Facebook, WhatsApp, WeChat, Line, Viber, Dropbox, Google Music, Google Books, and Google Videos.
This trick apparently only works for novice users.
