Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The TrickMo banking trojan can now capture Android PINs and unlock patterns
Global Security

The TrickMo banking trojan can now capture Android PINs and unlock patterns

AdminBy AdminOctober 15, 2024No Comments3 Mins Read
Android PINs and Unlock Patterns
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 15, 2024Ravi LakshmananMobile Security / Financial Fraud

Android PINs and Unlock Patterns

New variants of an Android banking trojan called TrickMo have been found to contain previously undocumented features to steal a device’s unlock pattern or PIN.

“This new addition allows a threat actor to act on a device even if it’s locked,” said Zimperium security researcher Aazim Yaswant said in an analysis published last week.

First spotted in the wild in 2019, TrickMo is named for its association with cybercriminal group TrickBot and is capable of providing remote control of infected devices, as well as stealing SMS-based one-time passwords (OTPs) and displaying overlays to capture credentials by abusing accessibility services Android.

Last month, Italian cybersecurity company Cleafy opened updated versions of the mobile malware with improved mechanisms to evade analysis and grant itself additional permissions to perform various malicious actions on the device, including conducting unauthorized transactions.

Cyber ​​security

Some of new options The malware has also been equipped to collect the device’s unlock pattern or PIN by presenting victims with a deceptive user interface (UI) that mimics the device’s actual unlock screen.

A UI is an HTML page that is hosted on an external website and displayed in full screen mode, giving the impression that it is a legitimate unlock screen.

When an unsuspecting user enters their unlock pattern or PIN, the information, along with the device’s unique identifier, is transmitted to a server controlled by the attacker (“android.ipgeo(.)at») in the form of an HTTP POST request.

Zimperium said the lack of proper protection of C2’s servers allowed it to gain insight into the types of data stored on them. This includes files from approximately 13,000 unique IP addresses, most of which are located in Canada, the UAE, Turkey and Germany.

TrickMo banking trojan

“These stolen credentials are not only limited to banking information, but also encompass those used to access corporate resources such as VPNs and internal websites,” Yaswant said. “This underscores the critical importance of protecting mobile devices, as they can serve as a primary entry point for cyberattacks on organizations.”

Another notable aspect is TrickMo’s broad purpose, collecting data from applications spanning multiple categories such as banking, enterprise, job and recruitment, e-commerce, commerce, social, streaming and entertainment, VPN, government, education , telecommunications and healthcare. .

This development comes amid the emergence of a new banking Trojan, ErrorFather Android, which uses a variant Cerberus carry out financial scams.

Cyber ​​security

“The emergence of ErrorFather highlights the continuing dangers of malware repurposing, as cybercriminals continue to exploit leaked source code years after the original Cerberus malware was discovered,” said Broadcom-owned Symantec. said.

According to data from Zscaler ThreatLabz, financially motivated mobile attacks using banking malware increased by 29% between June 2023 and April 2024 compared to the previous year.

India was the top target for mobile attacks during this time, experiencing 28% of all attacks, followed by the US, Canada, South Africa, the Netherlands, Mexico, Brazil, Nigeria, Singapore and the Philippines.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.