Riltok Banking Trojan
Riltok is a family of Android mobile banking trojans. First observed in early 2018 targeting Russian users, it has since been used in campaigns in Europe, North America and East Asia.
Summary
Riltok is a family of Android mobile banking trojans. First observed in early 2018 targeting Russian users, it has since been used in campaigns in Europe, North America and East Asia.
Affected platforms
The following platforms are known to be affected:
Threat details
All Riltok variants are distributed disguised as legitimate applications hosted through third-party sites. Users are directed to these sites through links sent in email or SMS spam campaigns, or through messages sent from previously compromised devices.
Once installed, Riltok will continually ask the user for full permissions until granted, before setting itself as the default SMS messaging application and hiding on the device. It will then scan the affected device for banking applications and use this information to tailor it's phishing pages, displayed whenever the user navigates to a corresponding site. Riltok will also display Google Play Services dialogue boxes requesting banking credentials.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:44 pm