New Android banking Trojan caught masquerading as Google Play update app
Android users beware! A new banking Trojan called "Antidot" has been discovered by cybersecurity firm Cyble. This malware disguises itself as a Google Play update app, targeting users across various regions in an attempt to steal your personal information.
Initially spotted on May 06, 2024, Antidot pretends to be a legitimate Google Play update, displaying a fake update page during installation. This page has been crafted in various languages, including German, French, Spanish, and English, suggesting a wide range of targets.
Once installed, Antidot utilizes overlay attacks to trick you into granting accessibility permissions. These permissions allow the malware to steal your data through various methods including VNC, Keylogging, Overlay attack, Screen recording, Call forwarding, Collecting contacts and SMSs, Performing USSD requests, Locking and unlocking the device.
"The emergence of sophisticated Android Banking Trojans poses a significant threat to users' security and privacy. Among these, the newly surfaced "Antidot" Banking Trojan stands out for its multifaceted capabilities and stealthy operations. Its utilization of string obfuscation, encryption, and strategic deployment of fake update pages demonstrate a targeted approach aimed at evading detection and maximizing its reach across diverse language-speaking regions," Cyble said in a statement.
This new Trojan highlights the evolving threat landscape for Android users. By staying vigilant and following security best practices shared by Cyble, you can significantly minimize the risk of falling victim to Antidot and similar malware:
Always install apps from trusted sources like the Google Play Store. Additionally, fortify your defenses with a reputable antivirus and internet security software on all your devices. Don't forget strong passwords and multi-factor authentication wherever possible. Finally, stay alert and avoid clicking suspicious links from SMS or emails.
Technical details about this Android banking Trojan can be found here.
Google News