Skip to main content

Android Banking Trojan Disguised as Flash Player

A banking trojan disguised as a Flash Player app, referred to as Android.banker.Af28a, has been observed on the Google Play Store.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A banking trojan disguised as a Flash Player app, referred to as Android.banker.Af28a, has been observed on the Google Play Store.

Affected platforms

The following platforms are known to be affected:

Threat details

Once downloaded, the malware requests administrative rights using pop-up dialogue boxes. It will continue to do this until access is granted, at which point it will hide it's icon before checking for 232 applications. If any are detected, a notification is displayed on behalf of the targeted app asking the user to login. User credentials, along with contact lists and SMS contents, are then sent to its command and control (C2) server. The malware can also intercept ingoing and outgoing SMS messages in order to bypass SMS-based two factor authentication.

Indicator of compromise

MD5 File Hashes

  • 29cf5cc309c2e29b6afd63eb5ab8fbd2

Package Name

  • yqyJqWdtdf.UOaOrquyRDgLFgGueha (Flash Player, 115KB)

Targeted Apps

android.banker.Af28a_app_110118.csv


Remediation steps

Type Step
  • Users are advised to only download legitimate and necessary applications, or should consider implementing a centrally-approved list of applications.
  • Applications should only be given reasonable permissions. Users should be suspicious of apps that ask for full administrative rights.
  • Users should ensure their mobile devices are full update.

Last edited: 17 February 2020 12:36 pm