In just 55 days, the Korbanker malware, which targets users' bank accounts, managed to intercept more than 10,000 messages from Android devices.
How it works:
Disguised as a Google Play App, it manages to trick users into stealing sensitive personal data. The malware detects mobile banking applications installed on the user's device and replaces them with a fake version.
It then intercepts two-factor authentication messages that allow access to users' bank accounts. All data is sent to a remote server where it is collected by the hackers.
The malware also steals two-step verification codes associated with Google and Facebook services, as well as passwords associated with VPN services.
Korbanker, due to the sensitive personal data it collects, poses a significant risk both to the average user and to the companies themselves, since hackers gain access to their infrastructures.
FireEye, a network security company, estimates that mobile malware may be part of a larger cybercriminal operation to steal sensitive personal data from internet users.

