Sunday, October 08, 2023

GoldDigger Malware: Its main goal is to steal banking credentials. | Tech Radar

There is no way of knowing exactly how many people fell for the trick and lost their money, but the warning is always the same - only download apps from legitimate sources and always be suspicious of links and attachments coming in through the mail. 
This particular Trojan has been active since at least June 2023. 
GoldDigger disguises itself as a fake Android application and can impersonate both a Vietnamese government portal and a local energy company. Its main goal is to steal banking credentials. Like many Android Trojans, the malware abuses Accessibility Service to extract personal information, intercept SMS messages, and perform various user actions. The Trojan also has a remote access capability.

Beware - GoldDigger malware will drain your bank accounts without you even realizing

Android
(Image credit: Future)

___________________________________________________________________________

Novo Malware Android GoldDigger rouba credenciais bancárias - BoletimSec
How does the GoldDigger Android malware steal your money?


Let's dig deeper: dissecting the new Android Trojan GoldDigger with  Group-IB Fraud Matrix | Group-IB Blog


2 days ago — The malware makes its way onto devices after users visit fake websites that manipulate them into downloading the app. Once installed, GoldDigger ...
1 day ago — Attackers have spoofed a Vietnamese government site and energy firm in creating malicious apps laced with GoldDigger, which exploits the ...
2 days ago — GoldDigger, a new Android malware, targets 50+ Vietnamese financial apps. With digital finance on the rise, the need for top-tier security is ...
3 days ago — How to remove GoldDigger malware from infected Android devices. Also ... malicious Android Trojan and similar threats in the ever-evolving threat ...
3 days ago — However, the malware also features translations into additional languages, hinting at plans for further expansion in Asia, Europe and South ...

___________________________________________________________________________


A dangerous new Android malware strain has been observed making the rounds, capable of stealing money from dozens of banking apps.

This alarm was sounded by cybersecurity researchers Group-IB, which spotted the new campaign in June this year. In this campaign, unnamed threat actors were delivering a piece of malware called GoldDigger. The malware was being delivered via two separate apps - one impersonating a Vietnamese government portal, and another one impersonating an energy company.

The attack vector itself wasn’t discovered, but the researchers are making an educated guess that the attackers were reaching out to victims via social media channels, email messages, and other usual methods. Through these channels, they were navigating the victims to at least a dozen fake Google Play websites, where they were offered to download the apps.

Accessibility and other red flags

Once on the device, the apps would do the usual - ask for the Accessibility permissions. This is also probably the best way to spot a malicious app - if it demands excessive permissions. If the victim grants these permissions, GoldDigger will start by digging out sensitive user information, including passwords. It will then look for any of the 51 Vietnamese financial organizations' apps, e-wallet apps, and cryptocurrency wallet apps. If it finds any, GoldDigger will seek out and exfiltrate the login data for them, essentially granting the attackers unobstructed access to the victim’s money. 

No comments:

ICE Barbie and Alleged Lover Face Ax as Trump Purges Goons

The Daily Beast: The Latest in Politics, Media & Entertainment News   ICE Barbie and Alleged Lover Face Ax as Trump Purges Goons CLEANIN...