A new Android trojan hidden inside a battery optimization app can steal money from users' accounts. ESET made the discovery today and confirmed that the trojan can even bypass 2-factor authentication, where it is enabled.

Fortunately, the malicious application, named Optimization Battery, is only available through a third-party app store and not through the Google Play Store, which in itself greatly limits its spread.
Beyond that, the application is classified as extremely dangerous and the reason for this classification is as follows. The trojan embedded in the application has a feature that automatically executes money transfers from each user's Paypal account, without giving them the opportunity to react. During its installation, the application requests the “Accessibility” permission, with which it can fake screen taps, as the user would do.
Once the malicious application is installed, it does not execute immediately. Instead, it waits for the user to run the Paypal application and then executes. After the user opens the application and logs in, the trojan begins executing. With quick movements, it navigates the menu and initiates a new money transfer to the attacker's account.
The entire process takes about 5 seconds, and the initial attempt is made with the amount of 1000 euros. The trojan is programmed to run every time the user opens the Paypal application. The only way to prevent the money transfer from being executed is for the amount of 1000 euros not to be available in the victim's account.
In the video below you can see how the trojan works. The movements are made so quickly that few will understand what happened, until they notice large amounts missing from their bank account or receive an email from Paypal about the money transfers they made.
