SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

News For You
News For You
Notifications

Beware of this Android malware that steals banking credentials from your phone

General
By 

Last updated: December 23rd, 2022 at 12:46 UTC+01:00

Update: A Google spokesperson has reached out with the following comment: “Google Play Protect checks Android devices with Google Play Services for potentially harmful apps from other sources. Users are protected by Google Play Protect, which blocks these identified malicious apps on Android devices.”

Experts at Group-IB, ThreatFabric, and Cyble have found a new Android banking malware called “Godfather” that has targeted users in 16 countries. The banking malware is speculated to be the successor of Anubis, which itself was once a very widely-used banking trojan by hackers.

According to reports, the Godfather Android banking malware has been targeting users in 16 countries by stealing their account credentials for over 400 online banking sites and cryptocurrency exchanges. It can mask itself as the login screen on top of the banking and cryptocurrency exchange websites' app login forums. When the user inputs his/her credentials, the information isn't submitted to the official website but is submitted to the hackers.

ThreatFabric spotted the Godfather banking malware in 2021, but according to the latest report by Cyble, the malware has undergone massive code changes and can now bypass the latest Android security measures. When the malware detects the affected endpoint and determines that the app language is Russian, Azerbaijani, Armenian, Belarusian, Kazakh, Kyrgyz, Moldovan, Uzbek, or Tajik, it shuts down. This is because the developers of this malware are believed to be of Russian origin.

The actual numbers of the infected devices aren't known yet, because infection via the Play Store is not the only way this malware has stolen banking and crypto exchange information from users. However, thanks to Cyble, one of the infected apps masks itself as MYT Müzik and has over 10 million downloads. Once downloaded, the app asks for permissions such as Google Protect and Accessibility Services.

After the permissions are granted, the app takes over the victim's SMS and notifications and starts recording the screen. It also extracts contacts, call lists, and more. The Godfather Android malware has targeted 215 banking apps, and most of them are located in the USA (49), Turkey (31), Spain (30), Canada (22), France (20), Germany (19), and the UK (17). Other targets of the Godfather malware include 110 cryptocurrency exchange platforms and 94 cryptocurrency wallet apps.

myt-muzik

General AndroidCanadaFranceGermanyMalwarePlay StoreRussiaspainTurkeyUKUSA
Galaxy AI summarized

Scroll for more related content
News For You

You might also like

Galaxy S21’s December 2024 security update rolls out to more variants

Galaxy S21’s December 2024 security update rolls out to more variants

Yesterday, Samsung released a software update to the carrier-locked variants of the Galaxy S21, Galaxy S21+, and Galaxy S21 Ultra, for the United States. It offered the December 2024 security patch that fixes several security issues present in the previous software. Now, the South Korean tech giant is rolling out the same software update to […]

  • By Abid Iqbal Shaik
  • 1 hour ago
One UI 6 Watch update reaches Galaxy Watch 4 in the USA

One UI 6 Watch update reaches Galaxy Watch 4 in the USA

A few days ago, Samsung's first Wear OS smartwatch, the Galaxy Watch 4, received the One UI 6 Watch update. The update was only available in a few markets at first. Now, it is finally available in the USA. Galaxy Watch 4 gets One UI 6 Watch update in USA The Galaxy Watch 4 and […]

  • By Asif Iqbal Shaik
  • 2 hours ago
The Galaxy A54 is picking up the December 2024 security update

The Galaxy A54 is picking up the December 2024 security update

It's raining updates today for a boatload of Galaxy devices. Several flagship Samsung smartphones have received the December 2024 security update this week, and a mid-range one has now been added to the list. The Galaxy A54 is picking up the December update in the USA. The update is available for some carrier-locked units. We're […]

  • By Abhijeet Mishra
  • 1 day ago
Galaxy S21 lineup grabs the latest security update

Galaxy S21 lineup grabs the latest security update

With two One UI 7 beta updates released for the Galaxy S24 series, Samsung is finally turning its attention towards the usual monthly updates for other Galaxy devices. This week, the December 2024 security update was released for the Galaxy S23 lineup, and it is now rolling out to the 2021 Galaxy S flagship models […]

  • By Abhijeet Mishra
  • 1 day ago
Samsung News app gets its first game, The Six, in North America

Samsung News app gets its first game, The Six, in North America

Samsung has announced that its news app, Samsung News, is doubling as a gaming app. It is getting its first game, The Six, which is already available on Samsung's smart TVs. Samsung News gets The Six trivia game The Samsung News app, which curates news from several sources, is getting its first game, The Six. […]

  • By Asif Iqbal Shaik
  • 6 days ago
Unknown Tracker Alerts will soon be actually useful on Galaxy phones

Unknown Tracker Alerts will soon be actually useful on Galaxy phones

While object location trackers like the AirTag and the Galaxy SmartTag are helpful, they can also be used to track others illegally. To neutralize that threat, Google introduced a feature called Unknown Tracker Alerts for Android phones. However, it wasn't very helpful earlier, and Google is trying to make amends by improving it. Unknown Tracker […]

  • By Asif Iqbal Shaik
  • 6 days ago