• About
  • Contact Us
  • Privacy Policy
  • Write for us
Saturday, May 28, 2022
  • Home
  • Blogging
    • SEO Tips
    • Make Money
    • Affiliate Marketing
    • Social Media
    • Web Hosting
    • Interviews
  • Business
  • Technology
    • Gadgets
    • Mobile
    • Tab
    • Internet
    • Downloads
  • Entertainment
    • Hollywood
    • Bollywood
    • Web Stories
    • Reviews
  • Sports
    • NFL
    • HFL
    • MLB
    • NBA
  • Games
    • Dota 2
    • Valorant
    • Fortnite
    • Among Us
    • Apex Legend
    • Rocket League
  • Featured
    • How to
    • What is
    • When is
    • Who is
  • Lifestyle
    • Fashion
    • Fitness
    • Health
  • Web Series
  • Home
  • Blogging
    • SEO Tips
    • Make Money
    • Affiliate Marketing
    • Social Media
    • Web Hosting
    • Interviews
  • Business
  • Technology
    • Gadgets
    • Mobile
    • Tab
    • Internet
    • Downloads
  • Entertainment
    • Hollywood
    • Bollywood
    • Web Stories
    • Reviews
  • Sports
    • NFL
    • HFL
    • MLB
    • NBA
  • Games
    • Dota 2
    • Valorant
    • Fortnite
    • Among Us
    • Apex Legend
    • Rocket League
  • Featured
    • How to
    • What is
    • When is
    • Who is
  • Lifestyle
    • Fashion
    • Fitness
    • Health
  • Web Series
No Result
View All Result
ONLYLOUDEST
No Result
View All Result
Home Downloads

2FA app with 10,000 Google Play downloads loaded well-known banking trojan

by Prahlad
January 29, 2022
Reading Time: 3 mins read
15
SHARES
1.5k
VIEWS
Share on FacebookShare on TwitterShare On LinkedIn

READ ALSO

Users can now download documents using WhatsApp Chatbot

Instagram tips: How to download Reels on Android phone, iPhone

2FA app with 10,000 Google Play downloads loaded well-known banking trojan

Getty Images

A fake two-factor-authentication app that has been downloaded some 10,000 times from Google Play surreptitiously installed a known banking-fraud trojan that scoured infected phones for financial data and other personal information, security firm Pradeo said.

2FA Authenticator went live on Google Play two weeks ago, posing as an alternative to legitimate 2FA apps from Google, Twilio, and other trusted companies. In fact, researchers from security firm Pradeo said on Thursday, the app steals personal data from user devices and uses it to determine whether infected phones should download and install a banking trojan already known to have infected thousands of phones in the past.

The vulturs are circling

Discovered last year by security firm ThreatFabric, Vultur is an advanced piece of Android malware. One of its many innovations is its use of a real implementation of the VNC screen-sharing application to mirror screens of infected devices so attackers can glean in real time the login credentials and other sensitive data from banking and finance apps.

To make 2FA Authenticator look real, its developers started with this legitimate sample of the open source Aegis authentication application. An analysis of the malware shows that it really was programmed to provide the authentication service it advertised.

Behind the scenes, however, stage one of the 2FA Authenticator collected a list of apps installed on the device along with the device’s geographic location. The app would also disable the Android lock screen, download third-party apps with the pretense they were “updates,” and overlay other mobile app interfaces to confuse users.

Advertisement

In the event infected phones were in the right locations and had the right apps installed, stage two of 2FA Authenticator would install Vultur, which at last check was programmed to record Android device screens when any of 103 banking, financial, or cryptocurrency apps are running in the foreground.

Pradeo said that 2FA Authenticator went live on January 12, that company researchers notified Google that the app was malicious on January 26, and that Google removed it about 12 hours later. Over the two weeks it was available in Play, the app was installed by about 10,000 users. It’s not clear if Google has notified any of them that the security app they thought they were getting was, in fact, a banking-fraud trojan.

In retrospect, there were red flags that experienced Android users could have spotted that 2FA Authenticator was malicious. Chief among them were the extraordinary number and breadth of system permissions it required. They included:

  • android.permission.QUERY_ALL_PACKAGES
  • android.permission.SYSTEM_ALERT_WINDOW
  • android.permission.REQUEST_INSTALL_PACKAGES
  • android.permission.INTERNET
  • android.permission.FOREGROUND_SERVICE
  • android.permission.RECEIVE_BOOT_COMPLETED
  • android.permission.DISABLE_KEYGUARD
  • android.permission.WAKE_LOCK

The official Aegis open source app code requires none of these permissions. App downloads posing as updates might be another telltale sign that something was amiss with 2FA Authenticator.

A review of 2FA Authenticator from one Google Play user.

A review of 2FA Authenticator from one Google Play user.

Pradeo

An email seeking comment from the developer address listed in the Google Play listing didn’t receive an immediate response. The same malicious 2FA Authenticator app remains available in third-party marketplaces here, here, and here. Google representatives weren’t immediately available for comment.

Prahlad

Prahlad

Howdy Geeks, I'm Prahlad, a young passionate blogger, entrepreneur & digital marketer from India. Blogging since 2019,Get me On Facebook Instagram

Related Posts

Downloads

Users can now download documents using WhatsApp Chatbot

May 27, 2022
Downloads

Instagram tips: How to download Reels on Android phone, iPhone

May 27, 2022
Downloads

How to download Stranger Things sticker pack in WhatsApp

May 27, 2022
Downloads

Everything You Need To Know About Download Festival 2022

May 27, 2022
Downloads

Why you should download apps with green badges from Softonic

May 26, 2022
Downloads

How to download the Ancient Egypt Mod for Minecraft: Pocket Edition

May 26, 2022
Next Post

New Taco Bell location opens for business in Erie

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Nutrisystem

POPULAR POSTS

Unblur Chegg Answers For Free

How To Unblur Chegg Answers For Free in 2022? [100% Working]

December 25, 2021
The Hindu PDF download

The Hindu PDF ePaper Free download Today – [current_date]

October 15, 2021
oreo tv apk download

Oreo TV APK Download v2.0.5 [ AdFree ] Latest Version 2022

December 2, 2021
Most liked reels influencer

Most liked reels influencer on Instagram – 20+ Content Creators With 1M+ Followers

July 30, 2021
bizgurukul review

Bizgurukul Review- Real or Fake? Scam Revealed!

December 25, 2021

EDITOR'S PICK

Seattle gaming startup Polyarc grows team as it brings 'Moss: Book 2' to Oculus

Seattle gaming startup Polyarc grows team as it brings ‘Moss: Book 2’ to Oculus

May 1, 2022

Sources: Chiefs ESC releases VALORANT roster

January 20, 2022

Gaachi Part 1,2 ULLU Web Series (2022) Watch Online – Telegraph Star

January 29, 2022
Europe's startups feel the pinch as Gorillas, Klarna cut staff |  PitchBook

Europe’s startups feel the pinch as Gorillas, Klarna cut staff | PitchBook

May 26, 2022

Categories

  • Affiliate Marketing
  • Among Us
  • Apex Legend
  • Blogging
  • Bollywood
  • Business
  • Dota 2
  • Downloads
  • Education
  • Entertainment
  • Fashion
  • Fortnite
  • Games
  • Hollywood
  • How to
  • Internet
  • Interviews
  • Make Money
  • Miscellaneous
  • MLB
  • NFL
  • Reviews
  • Rocket League
  • Search Engine Optimization (SEO)
  • Social Media
  • Tech
  • Valorant
  • Web Hosting
  • Web Series
  • What is
  • When is
  • Who is

About

OnlyLoudest is a Web magazine for Tech Lovers, Bloggers and entrepreneurs. We always share about online marketing and blogging.

ONLYLOUDEST OG

Follow us

Recent Posts

  • Pakistan Raises Fuel Prices as Economic and Political Crisis Deepens
  • Play Fortnite on iPhone: A New Workaround Brings the Game Back to iOS
  • Orca lets content creators make digital storefronts selling curated products–and they earn a 20% commission – Tubefilter
  • Hot Drop: Apex Legends Falls Short When It Comes To Valkyrie, Wattson, Maggie, And Rampart’s Muscles
  • Outer Harbor concert FAQs: How and when to get there, what to leave at home and more
  • About Us
  • Contact Us
  • Privacy Policy
  • Write for Us
  • Advertise With OnlyLoudest

Copyright 2013 - 2021 All Rights Reserved / OnlyLoudest - It's Never been that Simple!

No Result
View All Result
  • Homepages
  • Business
  • Entertainment
  • Tech
  • Downloads
  • Internet
  • Blogging
  • Reviews
  • Education
  • Social Media
  • Tech
  • Make Money
  • Search Engine Optimization (SEO)

Copyright 2013 - 2021 All Rights Reserved / OnlyLoudest - It's Never been that Simple!