Jump to content

Sneaky Android Malware Drains Users' PayPal Accounts Even With 2FA Enabled


The AchieVer

Recommended Posts

Android malware authors are always out looking to make a buck, and it looks as though one particular outfit has struck gold. Researchers from ESET have come across a malicious app called Optimization Android that presents itself as a battery conditioning tool.

androidoptimizer
Image Source: ESET
 

However, the app doesn't actually provide any power optimizations at all. Instead, it simply immediately shuts down when it's opened. However, in the background it is waiting to perform its dastardly deeds. When first installed, the app asks the user for permission to access AndroidAccessibility services, which is later cleverly used to infiltrate the PayPal payment service.

Here's how it works: the Android Accessibility permission allows the malicious app to monitor screen taps without the user noticing. So, Optimization Android lays in wait until the user opens the official PayPal app. Once PayPal is opened, the malicious app springs into action once the user enters his or her login credentials (along with their two-factor authentication code). Once this has been completed, the malicious app within 5 seconds uses these credentials to send funds from your account to the attacker's PayPal address.

 

In testing, the app attempted to steal 1,000 euros (although the currency depends on your given location). ESET writes:

Because the malware does not rely on stealing PayPal login credentials and instead waits for users to log into the official PayPal app themselves, it also bypasses PayPal’s two-factor authentication (2FA). Users with 2FA enabled simply complete one extra step as part of logging in, – as they normally would – but end up being just as vulnerable to this Trojan’s attack as those not using 2FA.

ESET adds that the attack will be successful as long as there are sufficient funds in your PayPal balance, or if you have a credit card attached to your account. As if all of the above wasn't enough, the malicious app can also obtain your contacts, make/forward calls and even intercept/delete SMS messages (among other things).

If there's any consolation to the discovery of Optimization Android, it's that thisspecific instance for now has only been found lurking within third-party app store and not the official Google Play Store. However, ESET notes that apps with similar functionality have been discovered in the Play Store.

 

Source

Link to comment
Share on other sites


  • Replies 1
  • Views 298
  • Created
  • Last Reply
25 minutes ago, The AchieVer said:

If there's any consolation to the discovery of Optimization Android, it's that thisspecific instance for now has only been found lurking within third-party app store and not the official Google Play Store. However, ESET notes that apps with similar functionality have been discovered in the Play Store.

Apparently there is no solution, even downloaded apps from Google Play Store.

 

If need to downloaded from third-party/Google Play store, what type of protection is advisable to have?, please. Thanks for he info.

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...