Technology by Design

Technology news, reviews, and how to keep your technology running fast and smooth!

  • Home
  • About TbyD
    • Who is TbyD
    • Why Choose TbyD?
    • 16 Things
    • Your Computer Guy
  • Products and Services
    • Business Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
      • Performance Analysis
      • Optimization
      • Core Security Solution
      • Managed Backups
      • Computer and Network Systems
      • Computer Setup
      • Domain Names
      • Email Services
      • Extended Warranties
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
      • Websites
    • Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
        • Computer Setup
      • Core Security Solution
      • Managed Backups
      • Extended Warranties
      • Performance Analysis
      • Optimization
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
    • Products
      • Computers
      • Servers
  • Testimonials
    • What Our Clients Say About Us
  • Blogs
    • ALERTS
    • FAQ
    • How To Videos
  • Newsletters
    • TechTips Newsletters
  • Reviews
  • Media
    • Email Red Flags
    • E-Books
    • Disaster Prevention Planning Kit
    • Free Reports
  • Contact Us
    • Contact Us
    • Quick Support

ALERT: Evil Android Trojan Empties Your Bank Account

May 17, 2016 by The T By D Team Leave a Comment

Mobile Device Trojan

ALERT:  Evil Android Trojan Empties Your Bank Account

The FBI has identified 2 versions of malware for Android (SlemBunk and Marcher) actively phishing for financial institutions’ customer credentials.  According to cyber threat security reports, both types of malware have targeted foreign financial institutions since 2014, gradually broadening the list to include Western banks, and offered the malware for lease or purchase in underground forums.

SlemBunk apps often masquerade as common, popular applications, and stay incognito after running the 1st time.  They have the ability to phish for, and harvest, authentication credentials when specified banking and other similar apps are launched.  Slembunk currently spoofs the apps of 31 banks across the globe – some of which are among the biggest banks in the world – as well as users of 2 popular mobile payment service provider apps.

Online Banking Login

Users will only get infected if the malware is accidentally downloaded from a malicious website, the new version of the malware being distributed by porn websites.  Users who visit these sites are incessantly prompted to download Adobe Flash update to view the porn, and doing so, downloads the malware.  

When the app is launched for the 1st time, it activates the registered receiver, which subsequently starts the monitoring service in the background.  On the surface, it pops up a fake UI claiming to be Adobe Flash Player, or whatever it was advertised as being, and requests to be the device admin.  Upon being granted admin privileges, it removes the fake icon from the device, and the malware monitors the infected phone for the launch of a targeted mobile banking app.  When a mobile banking/payment app is launched, the malware injects a phishing overlay over the legitimate banking/payment app’s user interface (aka login screen).  The malware then uses the fake login screen to steal the victim’s banking credentials.

How to Avoid Mobile Device Malware:
  1. If you receive a pop-up telling you that you need to download Adobe Flash or any other software, whether you’re on your desktop or on your mobile device, go directly to the Adobe website or the app store (type it in the address bar), and download it from there.
  2. Keep Android devices updated.
You can’t stop CyberCriminals from targeting your company or employees.
But you can be prepared for their arrival, and have full shields up.

Got CyberBugs?

Call 1-204-800-3166

For Cyber-Extermination!

#itthatworks

Filed Under: ALERTS, Blogs, Featured

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Sign Up For The Monthly TechTips Newsletter!

* = required field
unsubscribe from list

powered by MailChimp!

Recent Posts

  • ALERT: Celebrity Death Scams
  • ALERT: Uber Hacked
  • ALERT: Netflix Email Scam
  • ALERT: Bad Rabbit
  • Scam – Reset Password Alert

Recent Comments

  • ALERT: New Ransomware Targets MS Office 365 Users - Technology by Design on Managed Backups
  • ALERT: FBI Warns Email Extortion Heating Up for Summer! - Technology by Design on ALERT: AshleyMadison Hack Blows Up
  • ALERT: Evil Android Trojan Empties Your Bank Account - Technology by Design on Definition: Phishing
  • ALERT: HTML Attachments - Technology by Design on Definition: Phishing
  • ALERT: New Ransomware Also Steals Your Bitcoins - Technology by Design on Managed Backups

Copyright © 2025 · Dynamik Website Builder on Genesis Framework · WordPress · Log in