A botnet targeting Android smartphone users with accounts at financial institutions in the Middle East has been recently detected . The crude but highly effective mobile bot powering this whole operation comes disguised as one of many online banking apps, has infected over 2,700 phones and recorded at least 28,000 text messages.
The botnet comes embedded with Android apps that appear to have two-factor authentication features for various banks, including Riyad Bank, SAAB (formerly Saudi British Bank), AlAhliOnline (National Commercial Bank), Al Rajhi Bank, and Arab National Bank.
It is unclear how the apps are initially presented to victims, but previous such scams likely infect the victim's computer with a banking Trojan that steals passwords. Many banks send customers text messages containing one-time codes that are used to fill in a username and password when the customer logs in to the bank's Web site. To do this, attackers must hack the victim's phone to access this information.

