There have been a few trojans found on Android from time to time, but this is perhaps one of the worst. This new threat automates a $1000 PayPal transaction and sends it using PayPal's own official app, even to accounts with two-factor authentication (2FA).

This is done using different methods than before and by leveraging Android's accessibility services. The trojan is currently disguising itself as an Android optimization tool called Optimization Android and has reached users' phones through third-party stores. In addition to the official Play store, there are also third-party stores, so a word of advice to beginners: do not use third-party stores. Use only the Play store.
When you install the “Android Optimization” program, a service called “Enable statistics” is created. Of course, this service requests access to track user actions and retrieve window content.

But somewhere along the way, things start to get worse as the Trojan can mimic notifications. It creates a PayPal-like notification that prompts the user to log in.
When you tap the notification, it opens the official PayPal app (if installed) and asks the user to log in. Since this is a legitimate attempt to log in to the official Paypal app, 2FA does nothing to secure your account, other than sending you an additional code which, when entered, will log you in normally.
Once you log in, the malicious application takes over transferring $1000 from your PayPal account to the attacker. This automated process happens in less than five seconds. ESET made a video of the entire process, and it’s pretty crazy how quickly the whole process happens:
Once you realize what is happening, it is too late to stop it. The only thing that stops the process is that maybe your PayPal balance is too low and you have not added any other funding methods. So Paypal simply cancels the transaction due to lack of funds. Otherwise, you should realize this within a week and file a “non-acceptance of transaction” with Paypal, asking them to investigate and cancel the transaction, a process that takes at least 1 month.
But it doesn't end there. Not only does this trojan attack the user's PayPal account, it also uses Android's Screen Overlay feature to place rogue login screens on top of legitimate apps.
The trojan displays HTML overlay screens on Google Play, WhatsApp, Skype, and Viber, then uses them to steal credit card details. It can also create an overlay on Gmail, stealing the user's login credentials.
While the overlay attack is currently limited to the aforementioned applications, the list could be updated at any time, meaning this type of attack could be expanded at any point to steal any type of information the attacker wants. ESET's We Live Security service highlights that the attacker could explore other options using the overlay
