Beware - GoldDigger malware will drain your bank accounts without you even realizing

___________________________________________________________________________
___________________________________________________________________________
A dangerous new Android malware strain has been observed making the rounds, capable of stealing money from dozens of banking apps.
This alarm was sounded by cybersecurity researchers Group-IB, which spotted the new campaign in June this year. In this campaign, unnamed threat actors were delivering a piece of malware called GoldDigger. The malware was being delivered via two separate apps - one impersonating a Vietnamese government portal, and another one impersonating an energy company.
The attack vector itself wasn’t discovered, but the researchers are making an educated guess that the attackers were reaching out to victims via social media channels, email messages, and other usual methods. Through these channels, they were navigating the victims to at least a dozen fake Google Play websites, where they were offered to download the apps.
Accessibility and other red flags
Once on the device, the apps would do the usual - ask for the Accessibility permissions. This is also probably the best way to spot a malicious app - if it demands excessive permissions. If the victim grants these permissions, GoldDigger will start by digging out sensitive user information, including passwords. It will then look for any of the 51 Vietnamese financial organizations' apps, e-wallet apps, and cryptocurrency wallet apps. If it finds any, GoldDigger will seek out and exfiltrate the login data for them, essentially granting the attackers unobstructed access to the victim’s money.



No comments:
Post a Comment