A new trojan on Android steals your money through the official implementation of PayPal

Occasionally some trojans have been found on Android, but this is probably one of the worst. This new threat automates a $ 1000 PayPal transaction and sends it using the official PayPal application itself, even to two-point checking accounts (2FA).

This is done using different, up-to-date methods and leveraging Android's accessibility services. The trojan currently disguises itself as a named Android optimization tool Android and has reached users' phones through third-party stores. In addition to the official Play store, there are also third-party stores, so advice for beginners: do not use third-party stores. Use only Play Store.

When you install the "Optimization Android" program, a service called "Enable statistics" is created. Of course this service requests access to monitor users' actions and retrieve the contents of windows.

But somewhere things get worse as the Trojan horse can imitate alerts. Creates a notice that looks like these PayPal that pushes the user to connect.

When you tap the notification, it opens the official PayPal app (if installed) and asks the user to sign in. As long as it is a legitimate endeavor s in the official Paypal application, 2FA does nothing to secure your account, other than sending you an additional code which when you enter it you will log in normally.

After logging in, the malware takes over the transfer of $1000 from your PayPal account to the attacker. This automated one it happens in less than five seconds. ESET made a video of the whole process and it's pretty crazy how fast the whole process takes place:

Once you realize what's going on, it's too late to stop it. The only thing stopping the process is that maybe your PayPal balance is too low and you haven't added any other funding methods. So, Paypal simply cancels the transaction due to lack of funds. Otherwise, you should realize it within a weekand make a "transaction rejection" to Paypal, asking them to investigate and cancel the transaction, a process that takes at least 1 month.

But it does not end there. Not only does this trojan attack a user's PayPal account, but it also uses Android Screen Overlay to place illegal login screens on legitimate applications.

The trojan displays HTML overlays on Google Play, WhatsApp, Skype, and Viber, and then uses them to remove the credit card details. It can also create an overlay in Gmail by stealing user login credentials.

While the overlay attack is currently limited to the aforementioned applications, the list could be updated at any time, meaning that this type of attack can be extended at any point to steal any type s that the attacker wants. ESET's We Live Security service emphasizes that the attacker could explore other options by using the overlay

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).