A new banking Trojan targeting Androidhas been recently discovered and can receive instructions via SMS, suggesting that the attacker can monitor the activity of device owners.
Among the list of features is the ability to intercept incoming and outgoing SMS, and copy the contact list stored on the device. It can also interrupt incoming calls and end a conversation.
All information collected from the Banking Trojan-infected Android device is delivered to a C&C server, whose address is encoded within the malware.
Security researchers at Zscaler have observed that scammers are targeting mobile banking in China. After analyzing the threat, which appears to be a gaming app, they noticed that the credentials gathered on the C&C server are delivered to the attacker via email.
The same report states that some data can be selected and delivered via SMS to a Chinese phone number that is also encrypted in the banking Trojan script. The reason for this is that the remote server analyzes the texts it receives according to specific keywords and sends only the messages that contain bank account details.
As a security measure, many banks have adopted one-time password (OTP) authentication to somewhat ensure that the bank account is accessed by the real owner. Therefore, they must enter the verification code after their username and password to log in to their account.

