Red flags raised over fake banking apps

Researchers at IT security firm ESET have warned of the emerging threat of fake banking apps.

Research on the malware landscape for Android operating systems found that that cyber criminals have developed mobile banking malware that impersonates legitimate finance apps to obtain victims’ credentials, before stealing money from their bank accounts.

The analysis said that “while technically far from advanced”, these banking apps, which overlay mobile app platforms, have strategic advantages for criminals, meaning they are almost as effective at more sophisticated “Trojan horse” forms of malware hacks aimed at stealing money from unsuspecting consumers.

If users fall for the impersonation and install a fake banking app, there is a high chance they will treat the login screen displayed by the app as legitimate and submit their credentials, the researchers found.

Furthermore, contrary to banking Trojans, there are no intrusive permission requests to raise the users’ suspicion after installation.

Lukáš Štefanko, ESET malware researcher, said: “Our analysis of the two types of banking malware - both of which have previously been discovered in the official Google Play store - has shown that the simple operation of fake banking apps comes with certain advantages that the feared banking Trojans don’t have.

“While banking Trojans have long been regarded as a serious threat to Android users, fake banking apps have sometimes been overlooked due to their limited capabilities,” he concluded, adding that these apps could be just as valid a strategy for “emptying bank accounts as banking Trojans”.

    Share Story:

Recent Stories


Sanctions evasion in an era of conflict: Optimising KYC and monitoring to tackle crime
The ongoing war in Ukraine and resulting sanctions on Russia, and the continuing geopolitical tensions have resulted in an unprecedented increase in parties added to sanctions lists.

Achieving operational resilience in the financial sector: Navigating DORA with confidence
Operational resilience has become crucial for financial institutions navigating today's digital landscape riddled with cyber risks and challenges. The EU's Digital Operational Resilience Act (DORA) provides a harmonised framework to address these complexities, but there are key factors that financial institutions must ensure they consider.

Legacy isn’t the enemy: what FSIs can do to keep their systems up and running
In this webinar we will examine some of the steps FSIs have already taken to rigorously monitor and test systems – both manually and with AI-powered automation – while satisfying the concerns of regulators and customers.

Optimising digital banking: Unifying communications for seamless CX
In the digital age, financial institutions risk falling behind their rivals if they fail to unite fragmented communications ecosystems to deliver seamless, personalised customer experiences.

This FStech webinar sponsored by Precisely explores vital strategies to optimise cross-channel messaging through omnichannel orchestration and real-time customer data access.