A fake Android application disguises itself as a cleaning service to steal online banking credentials from customers of eight Malaysian banks.
The app is promoted through many fake or cloned websites and social media accounts to promote the malicious APK, «Cleaning Service Malaysia».

This app was first identified by MalwareHunterTeam last week and then analyzed by researchers at Cyble, who provide detailed information about the app's malicious behavior.
See also: Finland: Flubot banking malware infectsdevicesAndroid
Phishing process
During the installation of the application, users are asked to approve at least 24 permissions, including the dangerous «RECEIVE_SMS», which allows the app to monitor and read all SMS messages received on the phone.
This permission is used to monitor SMS texts for stealing one‑time passwords and MFA codes used in e‑banking services, which are then sent to the attacker’s server.

Once launched, the malicious application will display a form that asks the user to schedule a house cleaning appointment.

Once the user enters the details of his cleaning service (name, address, phone number) into the fake application, he is asked to choose a payment method.

This step offers a selection of Malaysian banks and internet banking, and if the victim clicks on one, they are taken to a fake login page created to mimic the appearance of the real one.
See also: 300,000 Android users have downloaded these banking trojan malware apps
This login page is hosted on the hacker's infrastructure, but of course, the victim has no way to notice it from the app's interface.

Any banking credentials entered at this step are sent directly to the hackers, who can use them together with an intercepted SMS code to access the victim's e-banking account.
Signs of fraud
Some clear signs of fraud in the social media accounts promoting these APKs are their low follower count and the fact that they were created very recently.
Another issue is the mismatch in the provided contact information. Because most of the decoy sites have chosen real cleaning services for imitation, the differences in phone numbers or email are a significant red flag.

And the requested permissions indicate that something is wrong, as a cleaning service app has no real reason to request access to a device's texts.
To minimize the chances of falling victim to phishing attacks of this kind, download only Android apps from the official Google Play Store.
See also: Mediatek fixed a bug that allowed call interception on Android
Additionally, always carefully check the requested permissions and do not install an app that asks for more privileges than those required for its functionality.
Finally, keep your device up to date by applying the latest available security updates and use a mobile security solution from a trusted provider.
Information source: bleepingcomputer.com
