DEAL Galaxy S24 FE, Galaxy Watch 7. Subscribe today and be the first to learn about One 7 beta!

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

News For You
News For You
Notifications

Beware of this Android malware that steals banking credentials from your phone

General
By 

Last updated: December 23rd, 2022 at 12:46 UTC+01:00

Update: A Google spokesperson has reached out with the following comment: “Google Play Protect checks Android devices with Google Play Services for potentially harmful apps from other sources. Users are protected by Google Play Protect, which blocks these identified malicious apps on Android devices.”

Experts at Group-IB, ThreatFabric, and Cyble have found a new Android banking malware called “Godfather” that has targeted users in 16 countries. The banking malware is speculated to be the successor of Anubis, which itself was once a very widely-used banking trojan by hackers.

According to reports, the Godfather Android banking malware has been targeting users in 16 countries by stealing their account credentials for over 400 online banking sites and cryptocurrency exchanges. It can mask itself as the login screen on top of the banking and cryptocurrency exchange websites' app login forums. When the user inputs his/her credentials, the information isn't submitted to the official website but is submitted to the hackers.

ThreatFabric spotted the Godfather banking malware in 2021, but according to the latest report by Cyble, the malware has undergone massive code changes and can now bypass the latest Android security measures. When the malware detects the affected endpoint and determines that the app language is Russian, Azerbaijani, Armenian, Belarusian, Kazakh, Kyrgyz, Moldovan, Uzbek, or Tajik, it shuts down. This is because the developers of this malware are believed to be of Russian origin.

The actual numbers of the infected devices aren't known yet, because infection via the Play Store is not the only way this malware has stolen banking and crypto exchange information from users. However, thanks to Cyble, one of the infected apps masks itself as MYT Müzik and has over 10 million downloads. Once downloaded, the app asks for permissions such as Google Protect and Accessibility Services.

After the permissions are granted, the app takes over the victim's SMS and notifications and starts recording the screen. It also extracts contacts, call lists, and more. The Godfather Android malware has targeted 215 banking apps, and most of them are located in the USA (49), Turkey (31), Spain (30), Canada (22), France (20), Germany (19), and the UK (17). Other targets of the Godfather malware include 110 cryptocurrency exchange platforms and 94 cryptocurrency wallet apps.

myt-muzik

General AndroidCanadaFranceGermanyMalwarePlay StoreRussiaspainTurkeyUKUSA
Galaxy AI summarized

Scroll for more related content
News For You

You might also like

Early Android 16 release could bring One UI 8.0 sooner

Early Android 16 release could bring One UI 8.0 sooner

Usually, Google releases a stable version of a new version of Android in the third or fourth quarter of a year. Take the last three versions of Android for example. The company released Android 13 in August 2022, Android 14 in October 2023, and Android 15 in October 2024. Well, Google will release the next […]

  • By Abid Iqbal Shaik
  • 3 hours ago
New awesome Nintendo Music app now available for Galaxy devices

New awesome Nintendo Music app now available for Galaxy devices

Nintendo has just released a new awesome app that fans of the brand and its iconic video games are bound to love. It's called Nintendo Music and does exactly what you think it does. It's kind of like Nintendo's own Spotify app and it is now available for Galaxy devices through the Play Store. Nintendo […]

  • By Mihai Matei
  • 1 day ago
Google Play Store is getting ready for Samsung’s XR headset

Google Play Store is getting ready for Samsung’s XR headset

It has been close to a year since Samsung first teased its upcoming extended reality (XR) headset on the stage. Since then, Google, Qualcomm, and Samsung have reiterated their commitment towards and plans for XR headsets. Now, it finally appears that Google is preparing the Play Store for Samsung's XR headset. Google Play Store will […]

  • By Abid Iqbal Shaik
  • 2 days ago
Samsung updates Galaxy A32 5G with October 2024 security patch

Samsung updates Galaxy A32 5G with October 2024 security patch

The Galaxy A32 5G is now almost four years old. While Samsung stopped offering new versions of Android to the smartphone a year ago, the company is still offering security updates to the smartphone as scheduled. As a part of that, the company has started rolling out the October 2024 security patch to the phone. […]

  • By Abid Iqbal Shaik
  • 2 days ago
Galaxy Note 20 5G’s October 2024 security update reaches USA

Galaxy Note 20 5G’s October 2024 security update reaches USA

Last week, Samsung released a software update to the Galaxy Note 20 5G that offered the October 2024 security patch. Back then, the company made it available in Europe. Now, the brand has released the update in the United States as well. Samsung is rolling out the update to the factory-unlocked as well as the […]

  • By Abid Iqbal Shaik
  • 2 days ago
Samsung’s device repair network welcomes 300+ more locations

Samsung’s device repair network welcomes 300+ more locations

Samsung's customer care network is expanding. The company announced today that its partnership with Cell Phone Repair (CPR) by Assurant, an Independent Service Provider (ISP) within Samsung's repair network, is opening more than 300 new service locations before the end of 2024. At the beginning of the year, CPR had roughly 100 locations certified by […]

  • By Mihai Matei
  • 3 days ago