Android Banking Trojan Disguised as Flash Player
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Once downloaded, the malware requests administrative rights using pop-up dialogue boxes. It will continue to do this until access is granted, at which point it will hide it's icon before checking for 232 applications. If any are detected, a notification is displayed on behalf of the targeted app asking the user to login. User credentials, along with contact lists and SMS contents, are then sent to its command and control (C2) server. The malware can also intercept ingoing and outgoing SMS messages in order to bypass SMS-based two factor authentication.
Indicator of compromise
MD5 File Hashes
- 29cf5cc309c2e29b6afd63eb5ab8fbd2
Package Name
- yqyJqWdtdf.UOaOrquyRDgLFgGueha (Flash Player, 115KB)
Targeted Apps
Remediation steps
Last edited: 17 February 2020 12:36 pm