When Google restricted the use of SMS and Call Log permissions in Android apps in March 2019, one of the positive results was that credential-stealing apps lost the option to abuse these permissions to bypass two-factor authentication (2FA) mechanisms.
Unfortunately, however, malicious apps have recently been found that access one-time passwords (OTPs) in SMS 2FA without using SMS permissions, bypassing Google's recent restrictions. As a bonus, this technique also works to obtain OTPs from some 2FA systems.

The apps mimic the Turkish cryptocurrency exchange BtcTurk and perform a phishing attack to steal login credentials to the service. The malicious apps obtain the OTP from notifications displayed on the victim’s screen. In addition to reading 2FA notifications, the apps can also hide them so that victims don’t understand the attack.
Malware, all forms of which are detected by ESET , is the first to bypass the new SMS permission restrictions.

The first of the malicious apps detected was uploaded to Google Play on June 7, 2019 as “BTCTurk Pro Beta” under the developer name “BTCTurk Pro Beta”. It was installed by more than 50 users before being reported by ESET to Google’s security teams. BtcTurk is a Turkish cryptocurrency exchange. The official mobile app connects to the exchange’s website and is only available to users in Turkey.
The second app was uploaded on June 11, 2019 as “BtcTurk Pro Beta” under the developer name “BtSoft.” Although the two apps use a very similar formation, they appear to be the work of different attackers. The app was reported on June 12, 2019, when it had been installed by fewer than 50 users.

After the removal of this second app, the same attackers uploaded another app with the same functionality, this time named “BTCTURK PRO” and using the same developer name, icon and screenshots. The app was reported on June 13, 2019.
For more technical details click here.
