The yellow metal is supported by a revival in demand from Chinese consumers and healthy purchasing activity by central banks, expert says
This mobile banking Trojan abuses Android's in-built accessibility features to steal user data, read user SMS messages and intercept SMS messages, allowing malware to bypass two-factor authentication, the cybersecurity agency said in its advisory this month.
EventBot targets over 200 different financial applications, including banking applications, money-transfer services, and cryptocurrency wallets, or financial applications based in the US and Europe region at the moment but some of their services may affect Indian users as well.
The malware largely targets financial applications like Paypal Business, Revolut, Barclays, UniCredit, CapitalOne UK, HSBC UK, TransferWise, Coinbase, paysafecard etc., said CERT-In.
While EventBot has not been seen on Google Play Store yet, it uses several icons to masquerade as a legitimate application.
EventBot is using third-party application downloading site to infiltrate into the victim device, the CERT-In warned.
"Once installed on victim's Android device, it asks permissions such as controlling system alerts, reading external storage content, installing additional packages, accessing Internet, whitelisting it to ignore battery optimisation, prevent processor from sleeping or dimming the screen, auto-initiate upon reboot, receive and read SMS messages, and continue running and accessing data in the background," the cybersecurity agency said in its advisory.
Further, the malware prompts the users to give access to their device accessibility services.
"Also, it can retrieve notifications about other installed applications and read contents of other applications. Over the time, it can also read Lock Screen and in-app PIN that can give attacker more privileged access over victim device," the advisory said.
To help users prevent the malware infection into Android phones, the cyber-security agency recommended certain counter-measures.
"Do not download and install applications from untrusted sources (offered via unknown websites/ links on unscrupulous messages)," it said.
It also asked users to install updated anti-virus solution on Android devices.
The yellow metal is supported by a revival in demand from Chinese consumers and healthy purchasing activity by central banks, expert says
The Lives and Livelihoods Fund is the largest multilateral fund of its kind in the Middle East
Stock market opened with modest gain on Wednesday marking third consecutive session in the upward gain
Union warned it could order several days of strike action over a busy May holiday weekend if its demands are not met
Humidity is set to rise during the night and into Thursday morning
Text messages, social media posts, chatroom messages, altered images, and videos are just a few avenues through which cyberbullying can occur
The building in Muhaisnah 4 had suffered structural damage last week and has been sealed off as authorities conduct investigations
Al Ain, which knocked out Cristiano Ronaldo's Al Nassr in the quarterfinals, reached the final for the first time since 2016