216.73.217.22

"Sneaky" new Android malware takes over your phone, hiding in fake news and ID apps

· Published 05/11/2025 12:36 · Modified 05/11/2025 21:49

Export JSON

Essential information

Published
05/11/2025 12:36
Modified
05/11/2025 21:49
Tags
2025-11-05 accessibility services android android/trojan.spy.banker.aur9b9b491bc44 banking malware cryptocurrency overlay attack southeast asia trojan
Related entities
3 techniques (mitre), 1 others

Description

A sophisticated has been discovered that masquerades as trusted apps like news readers or digital ID applications. Once installed, it quietly operates in the background, stealing sensitive information such as login credentials and financial data. The malware exploits 's and overlay features to gain control over the device and capture user inputs. It targets banking and apps, primarily in , by overlaying fake login screens to steal credentials. The also connects to a remote command center, allowing attackers to update its functionality and erase traces of its activity. This threat emphasizes the growing need for robust mobile security measures.

External references