A software company, Cheetah Mobile has identified a malicious piece of Android malware that replaces legitimate banking apps with fake versions.
According to Cheetah Mobile's report, the Trojan disguises itself as a popular game or third-party apps in Android app markets in Korea and tricks users into installing the app.
Once installed, the Trojan searches for the official online banking applications of South Korean banks, including Nong Hyup Bank, Sinhan Bank, Woori, Kookmin, Hana Bank N, Busan Bank, and the Korean Federation of Community Credit Unions.
If one of these banking apps is found to be installed on the victim's device, the malware displays a warning saying that the banking app needs to be updated. Once the update is approved, the legitimate banking app will be replaced with the fake one.
The fake version then asks victims to enter the password to their security certificate (which is required by the South Korean government in order to access many online services).
The app then asks victims to provide their bank account number, passwords, and bank security number.
In the end, the malware simply displays a fake error message informing victims that there is no Internet connection. The malware then deletes itself from the device.
"With the stolen information, hackers can apply for a new certificate, which is then used to gain unrestricted access to the victim's bank account," Cheetah Mobile claims.
The company said that over 3,000 devices have been infected in the last week alone.

