How does the new Trojan work? Ways to prevent money theft from your smartphone

How does the new Trojan work? Ways to prevent money theft from your smartphone

Analysts from the Russian cybersecurity company "F6" have exposed a dangerous Android Trojan that poses a threat to the bank accounts of users in Uzbekistan and Kazakhstan. Between May and September of this year, more than 800 samples of the RedWing Stealer malware were detected.

Disguised as ordinary and popular applications, this virus is specialized in directly stealing money from bank cards and accounts.

Under the disguise of which apps is it spreading and who is targeted?

Cybercriminals have cleverly hidden the malicious code inside apps that people frequently download:

  • List of masked applications: The Trojan has been distributed in the guise of VPN services, gas station maps, drone-detecting radars, 18+ video platforms, as well as cheats and mods for popular mobile games;

  • Targeted financial institutions: Researchers note that the malware aims to steal data from customers of 12 major banks in Uzbekistan and 7 in Kazakhstan.

The virus's mechanism of action: How are bank codes obtained?

Once installed, RedWing Stealer establishes almost complete control over the phone:

  • Reading SMS and messages: The program opens and reads one-time confirmation SMS codes and push notifications coming from the bank, immediately sending them to the fraudsters;

  • Controlling the device: It steals the phone model, location (GPS), SIM cards, call history, and contacts. It is also capable of independently sending paid SMS or USSD requests;

  • Hiding itself and requesting a PIN code: After installation, it hides its icon on the app screen. Later, it displays a fake window demanding the user to enter a PIN code and transfers this information into the hackers' hands as well.

Expert recommendations: How to protect money on your card?

Cybersecurity experts advise smartphone owners to strictly follow these security rules:

  • Do not download suspicious APK files: Never install files from Telegram channels, unknown SMS messages, spam advertisements, or unverified sites;

  • Restrict settings: Turn off the "Install from unknown sources" feature in your smartphone settings;

  • Check permissions: If ordinary applications unreasonably request access to SMS, contacts, or the "Accessibility" section, uninstall them immediately;

  • Actions when danger is detected: If you notice a suspicious application appearing on your phone, immediately change the passwords of your important accounts using another device, check your banking operations, and contact your bank to block your cards.

Comments 0

…

Related news