HomeSecurityBanking Trojans: huge cyber threats for mobile

Banking Trojans: huge cyber threats for mobile

For this reason alone, we can confidently say that banking Trojans are the most significant mobile threats, as they constitute over 95% of mobile malware.

We are in an era where the majority of smartphone users still consider their device “just a phone,” unlike PC users who already use at least a basic “security hygiene” against Trojans.
Smartphones today are complete computers. And more specifically, they are dangerous computers. Where your computer’s hard drive may not contain anything of value, your smartphone is very likely to contain data that is valuable to both you and cybercriminals.
If you have a smartphone, it is very likely that you also have a bank card. Since banks use your mobile phone number for authentication (they send one-time passwords via SMS), it is possible that cybercriminals have tried to infiltrate this communication channel and execute payments and transfers from your bank account.

Banking Trojans: huge cyber threats for mobile

For this reason alone, we can safely say that banking Trojans are the most significant mobile threats, as they account for over 95% of mobile malware.
Although Trojans are less dangerous than viruses, since they require user action to infiltrate systems, there are a number of effective social engineering techniques that trick the user into activating them through fake updates.
There are three main methods banking Trojans employ:
• Text cloaking: Mobile malware cloaks incoming SMS messages from banks and then sends them to criminals who then transfer money to their accounts.
• Small cash transactions: Malware actors occasionally transfer small amounts of money to scam accounts from an infected user’s account.
• App Mirroring: Malware mobile applications that imitate banks and take the user's login credentials from the real application.
Major banking Trojans (over 50%) target Russia and CIS countries, as well as India and Vietnam. Lately, a new generation of universal mobile malware has been on the rise.
The granddaddy of all mobile banking Trojans is Zeus, also known as Zitmo (Zeus-in-the-mobile), created since 2010 (successor to Zeus for computers from 2006). This piece of malware managed to infect over 3.5 million devices in the US alone and create the largest botnet in history.
Thanks to Zeus, the crooks managed to get away with over 74,000 FTP passwords from various websites (including Bank of America), changing their password so that it would be possible to extract credit card data after each payment attempt. Zeus was very active until late 2013, when it was dethroned by the more modern Xtreme RAT.
Over time, we saw banking Trojans make their appearance. In 2011, we saw SpyEye, which was one of the most successful banking Trojans in history. In 2012, another type of Trojan was found – Carberp. This component imitated Android applications of major Russian banks, Sberbank and Alfa Bank, as it targeted their users in Russia, Belarus, Kazakhstan, Moldova and Ukraine. Curiously, the perpetrators were able to publish fake applications on Google Play.
Moving on to the most recent incidents, in 2013, Hesperbot began looking for its own victims. It was a malware originating from Turkey and in addition to the usual problems, this Trojan creates a hidden VNC server on a smartphone, which provided access to an attacker for remote management of the device. Moreover, Hesperbot acted not only as a banking Trojan, but also as a Bitcoin.
Accordingly, in 2014 the source code of Android.iBanking was revealed. iBanking is an end-to-end kit for SMS hi-jacking and remote device management. The publication of the code led to an increase in infections.
In June 2015, a new Trojan was discovered in Russia. Android.Bankbot.65.Origin was disguised as a patched official Sberbank Online application and offered a “wider range of m-banking features”, available after installing the “newer version”.

Banking Trojans: huge cyber threats for mobile
In fact, the application remained a functional m-banking tool, so no user noticed the change. As a result, in July 100,000 Sberbank users reported losses of over 2 billion rubles. All of them used the fake “Sberbank Online” application.
It goes without saying that the history of banking Trojans is still being written: more and more new applications are created, and attackers use more and more effective techniques to lure users into their trap. So, it’s time to protect your smartphone properly!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS