Faketoken Android Trojan: Researchers at Kaspersky Lab have discovered a new modification of the well-known mobile banking Trojan Faketoken, which has been developed and is now capable of stealing personal data from popular taxi service applications.
The mobile apps market is growing and offering increasingly more services that store confidential financial data, including applications for taxi services and ride-sharing apps that require users' bank account information. 
The fact that these apps are installed on millions of Android devices worldwide makes them more attractive to digital criminals, who have significantly expanded the functionality of malicious mobile banking software.
The new version of Faketoken performs live monitoring of apps and as soon as the user «runs» a specific app, it overlays it with an electronic phishing window to steal the victim's bank account details.
The Trojan maintains the same interface, using the same designs, colors and logos, automatically creating an invisible overlay. Based on the results of Kaspersky Lab's research, criminals target this malicious software at the most popular international ride‑hailing and vehicle‑sharing applications.
Additionally, the Trojan intercepts all incoming SMS messages and transfers them to its command and control servers, allowing criminals to access unique verification codes sent by banks or other messages sent by various transportation services. Among other things, this Faketoken modification can monitor users' calls, record them, and transmit the resulting data to the command and control servers.
The overlay is a common feature that is enabled in many mobile applications. In 2016, Kaspersky Lab reported a modification of Faketoken that attacked more than 2,000 financial applications worldwide, «disguised» as various programs and games, often mimicking the Adobe Flash Player. Since then, Faketoken has further developed and expanded its activities geographically.
“The fact that cybercriminals have expanded their activities from financial applications to other sectors, including taxi and ride-sharing services, means that developers of these services may want to pay more attention to protecting their users. The banking industry is already familiar with fraud schemes and scams and has reacted by implementing security technologies in applications, thereby significantly reducing the risk of theft of critical financial data. Perhaps now is the time for other services that involve transactions with financial data to follow suit. The new version of Faketoken primarily targets Russian users. However, the geography of its attacks could easily expand in the future. We have seen this with previous versions of Faketoken and other banking malware in the past,” said Viktor Chebyshev, security specialist at Kaspersky Lab.
Researchers also detected attacks of the Faketoken Android Trojan on other popular mobile applications, such as travel and hotel booking apps, traffic fine payment apps, Android Pay and Google Play Market.
To protect themselves from the Faketoken Android Trojan and other Android malware threats, Kaspersky Lab recommends users not to install applications from unknown sources.
More information about the new version of the Android malware Faketoken can be found on the dedicated website Securelist.com.
