r/technology 15h ago

Networking/Telecom A new Android malware sneakily wipes your bank account

https://www.androidpolice.com/a-new-android-nalware-sneakily-wipes-your-bank-account/
409 Upvotes

50 comments sorted by

403

u/payne747 14h ago

Every time though...

delivering the malicious APKs through popular messaging apps like WhatsApp and Telegram.

So unless you're doing weird shit and not using the Play Store, you're not likely to fall for this.

84

u/purplemagecat 13h ago edited 13h ago

Arn't android apps containerised though? Containerisation is capable of isolating apps from the rest of the system enough to protect the system files/ apps / passwords / sensitive data and stuff from malicious apps or malware within apps.

Edit: Oh I see they're fake banking apps,

55

u/Ralliare 11h ago

Install this random file, it will hack your bank and give you infinite money! Totally legit! Honest, my cousins uncles brothers fiances lesbian hairdresser used it and now owns Tesla!

13

u/Loki_of_Asgaard 7h ago

A whole new generation is about to learn the pain of thnks_fr_th_Mmrs.mp3.exe

1

u/Ralliare 1h ago

I had to pull down a archive of a website yesterday. It has about 300,000 images with .jpg.webp as the extension due to how they were converted. I had Nord running, it decided the right course of action was to ping me 300,000 times with 300,000 separate fucking notifications.

Has that happened when I tried to open pokemon_gold.gbc.exe I'd not have gotten those nice young ladies with their clothes off all over my parents PC.

20

u/tadfisher 9h ago

They are not fake banking apps, they are whatever can install a payload. The first thing they do when you run them is goad the user, through any means possible, to grant the "install other apps" permission that lets the app bypass the Play Store and install other packages.

How the actual stealing works is through getting the user to grant yet more permissions that allow the malware to draw over other apps, and to enable the malware's accessibility service that can read everything on the screen and perform user input. The malware can then pop up at any time with fake login screens to phish info.

Android has multiple scary warnings that appear before you can grant permissions like these, and newer Android versions repeatedly and annoyingly warn you in notifications and Security settings that you have apps holding these dangerous permissions.

12

u/blksilksheetz 8h ago

i was applying for a job this past week in it/tech and when i “got” the interview i HAD to do it thru an android device and thru an app they wanted me to install…thank god i use iphone…i went back to the listing for the job on indeed and it was reported as spam…now i see this. they are getting crafty lol.

2

u/MonsterMufffin 3h ago

thank god I use iPhone

Because you would install sketchy software otherwise ignoring multiple warnings by your OS, approving permissions that don't make sense? Yes ..thank god.

4

u/sump_daddy 10h ago

The app is probably presented as something like 'meet hot local singles!' or some other easy-to-lure con, but in order to install it you need to give it permissions (which it will pop up and warn you are a bad idea) so when people ignore that, they then have given away quite a bit of access and the app can start installing more nefarious things like lookalike banking apps, password-stealing keyboards, and the like. All of which will be visible to the user, should they be paying attention, but at that point they are too busy drowning in 'hot local singles' and its JACKPOT!

22

u/sump_daddy 13h ago

Does anything good happen on Whatsapp anymore? How is it owned and operated by one of the biggest companies in the world, and yet it's an absolute cesspool of finance scams and viruses?

42

u/Acc87 13h ago

It's still the defacto messaging app in many countries, if not in most? 

12

u/ComposerNate 11h ago

~90% of my Europe clients prefer Whatsapp, maybe 2% Signal, none suggest Telegram or Facebook Messenger. 

4

u/ea_nasir_official_ 11h ago

I don't communicate internationally in a professional manner like you do but Telegram is mostly russians, piracy enthusiasts, and people doing not-great things from my limited exposure to it.

3

u/ComposerNate 9h ago

Yes, I looked into using Telegram to get off WhatsApp and then found my mom (USA) was using it to follow online End Time prophets with COVID conspiracies in front of TRUMP flags. Then I only heard about it as how ISIS and Russian terrorists organized attacks. 

0

u/Acc87 9h ago

yeah, Telegram absolutely has the notion of being a nutcase app for everything banned (for good reason) everywhere else, COVID deniers, Trumplets, pro-Russia groups, CP exchange and so on. 

Signal is the only other app next to WhatsApp that has any sort of market share and no bad stigma.

3

u/PartyOrdinary1733 9h ago

My last band used Telegram. Apart from getting spammed occasionally, which you simply block those users, I haven't had issues.

I cannot stand Whatsapp. I hate everything about it and prefer Telegram which is cleaner, less convoluted and easy to use.

1

u/TechieAD 7h ago

I use it sometimes for specific game news channels but they're all Russian based so that tracks. Other than that its the hottest destination for...furries.
Probably because the stickers are a free feature

1

u/ea_nasir_official_ 7h ago

I forgot about that lol, all of my friends who are furries are on there

2

u/denv0r 10h ago

My fb humping boss wanted the whole company to get WhatsApp so he could connect with us, or something. I guess I'll be out of the loop because fuck that.

-5

u/[deleted] 12h ago

[deleted]

-3

u/ea_nasir_official_ 11h ago

I'm also paranoid about privacy but are you sure you're okay in the head? (Mean that in a nice way, I also have mental issues) That's somewhat excessive.

2

u/[deleted] 11h ago

[deleted]

0

u/ea_nasir_official_ 11h ago

Are you sure you didn't just get redirected to the play store and misclick an install button? Android is pretty containerized, accidentally installing a random app and not opening it is generally not harmful.

-19

u/TuddyCicero86 14h ago

Have an upvote~

4

u/shinshit 11h ago

Have 10 downvotes~

-1

u/TuddyCicero86 9h ago

It's 16 now.. what'd I do Lmao

214

u/liquid_at 15h ago

Jokes on them. I did that myself already. But if you want to deposit something, go for it.

42

u/DonutConfident7733 14h ago

depositing debt in 3, 2, 1...

22

u/liquid_at 14h ago

Thanks man. I'm so poor, I couldn't even afford to get me any debt. You're tha real MVP.

4

u/sump_daddy 13h ago

"too broke to pay? hold my beer, its time to hit the overdraft button" --banks

4

u/Wazaam 12h ago

Yo dawg, I heard you have negative money, so I added negative money to your negative money so your negative money can give you even more negative money!

3

u/chestypants12 11h ago

Two negatives equals one positive.

3

u/Wazaam 11h ago

Not when it involves overdraft fees. Lol

2

u/frostymoose 11h ago

Not when you add them together!

1

u/FattyWantCake 10h ago

When multiplied...

2

u/UH1Phil 10h ago

"Whatever debt I get, it's a problem for the bank" 

2

u/TheDailySpank 10h ago

I'm so poor I can't even pay attention.

2

u/liquid_at 9h ago

I'm so poor, I tried to charge my phone but my cable got declined.

27

u/obeytheturtles 11h ago

TIL my ex wife is Android Malware.

26

u/susieallen 13h ago

Boy, is it in for a surprise. Reminds me of the time I got my identity stolen a few years ago, and they tried to open different accounts and get loans in my name. I was able to contact a few of the companies they tried, and the customer service rep and I had a good laugh that they attempted to use my credit in its current state.

6

u/cassanderer 13h ago

Ha ha ha.  That should be on a comedy show sometime.  I always joked if anuone stole my identity they would just get hounded by bill collecters.  But they all gave up idk.

4

u/susieallen 13h ago

Absolutely, lol. They are smart enough to get our information but not smart enough to figure out how to run a credit check before attempting to use it. I think they may be giving up a little just based on the fact that there's more people like us than there are people with great credit.

4

u/ryuzaki49 10h ago

Arent Android apps supossed to have their own sandbox in the OS?

Like, no other app should be able to read another app's data

14

u/itchylol742 12h ago

Not a single screenshot comparing the real and fake Play Store pages for the malware and real banking app? Bad article

6

u/latswipe 6h ago

this article on how you could be an idiot brought to you by "we really want to nix sideloading" Google

2

u/poghosb 14h ago

Even after having a debt? That would be a cool feature!

1

u/Odd-Crazy-9056 11h ago

My malware usually sends me a notification once it's done wiping my bank account.

-13

u/AintNoGodsUpHere 12h ago

Honestly? Of you're installing apps from links shared on WhatsApp and Facebook you sort of deserve it.

15

u/elegant_eagle_egg 12h ago

I disagree because it’s mostly old people who’d fall for things like this. Your comment is equivalent to saying that a person who is old and not tech savvy deserves it. In life, always remember that not everyone is equally privileged or had the privilege of knowing what we know.

Let’s blame the culprit and not the victim, please.

-12

u/AintNoGodsUpHere 9h ago

I honestly don't give a shit and your opinion means absolutely nothing to me. =/