A slightly altered version of Assassin's Creed, for Android, provides not only a great gaming experience, but also dangerous malware, which runs in the background.
The game appears to function normally from the user's perspective, as its features are not altered, but it includes additional code designed to relay text messages received by the user to a server controlled by fraudsters.
Security researchers at ZScaler analyzed the sample and determined that it was monitoring SMS messages received by the owner of the mobile phone from phone numbers belonging to the Russian Bank Volga-Vyatka, Sberbank, Russia.
This particular sender is being monitored, likely due to the sensitive information it provides to customers who have activated the 2FA security measure for their access to bank accounts.
According to ZScaler, the information collected from the victim's device is sent to the attacker at a specific frequency. There are two C&C (command and control) server addresses encoded in the malware code, pointing to, bnk7ihekqxp [..]NET and googleapiserver [..]net.
The malware 's list of permissions also includes processing outgoing calls, as well as reading and writing to external storage. It also asks for user permission to launch at device startup.
“Cybercriminals often lure users with pirated versions of popular mobile apps that are Trojanized in order to steal sensitive information. It is recommended that users stay away from such offers and only download apps from trusted sources such as the Google Play Store,” ZScaler said in a blog post.
Currently, at least 12 out of 56 antivirus programs on Virus Total can detect the malware. However, users do not rely on antivirus protection for their mobile devices.
Additionally, it is very common for users to not pay attention to the permissions an app requests when installing. In the case of third-party apps, the legitimacy of the permissions is not checked, and scammers could release software that requests more than it should.

