Skip to main content

Zitmo trojan attacking Android bank transactions

Image used with permission by copyright holder

Zitmo, a Trojan spyware app that poses as banking activation software, has now been modified to attack Android-based devices. The virus, which steals financial transaction information, has previously been successfully used on Symbian, BlackBerry and Windows Mobile devices.

Axelle Apvrille, an author at the security blog Fortinet, said Zitmo is being put to use by the ZeuS botnet gang.

“The malware poses as a banking activation application,” she said. “In the background, it listens to all incoming SMS messages and forwards them to a remote Web server. It’s simple, but just enough for the ZeuS gang to grab your banking mTANs.”

MTAN stands for “mobile transaction authentication number” or, if you’re not a banker, a single-use password for approving bank transactions while you’re on the go. MTANs are sent by text message between the bank and customer, and are recommended for use by the Federal Financial Institutions Examinations Council because they offer a type of authentication that doesn’t go through regular channels. In other words, they are supposed to be harder to crack.

The Zitmo attack works because ZeuS figured out how to get in early. The malware first infects a user’s PC and waits for the user to visit their bank site on their phone. Posing as a new layer of security software, Zitmo prompts users to download itself. When that happens, it controls the user’s PC and phone, and will continue sending crucial information to outside parties.

Editors' Recommendations

Derek Mead
Former Digital Trends Contributor
The camera on this Android phone is confusing, but I love it
The back of the Tecno Camon 30 Premier.

I’m all for a lot of detail, and love to hear about the new technology that’s inside a smartphone I’m about to test, but when I have to search for an explanation of what something means, it’s not a good start. The Tecno Camon 30 Premier suffers from this problem, as it has a lot of cool camera tech that is explained in a mystifying way.

So, I thought the best thing to do was to just ignore the tech speak and find out if it takes great photos the old-fashioned way.
What's the problem?

Read more
The 5 best phones with IR blasters in 2024
The OnePlus 12's camera module.

IR blasters used to be a common component in smartphones, with big products from Samsung, OnePlus, and TCL giving users access to the cool gadget. Phones equipped with IR blasters could be used as a universal remote for your other electronics, making it easy to control your gear without the need for their default controller (which might be clunky and unintuitive to use).

Fast forward today, and attempting to find a smartphone with an IR blaster is shockingly difficult. What was once common technology is now relegated to just a handful of smartphones. You won't find any iPhones or Galaxy phones with IR blasters, but that doesn't mean you have to settle for a poorly reviewed smartphone if you're interested in the tech. You will, however, probably need to settle for either OnePlus or Xiaomi, as they're the two key players still churning out powerful smartphones equipped with IR blasters.

Read more
Why you should buy the iPhone 15 Pro instead of the iPhone 15 Pro Max
Natural Titanium iPhone 15 Pro with Chopper and BD-1 droids around it.

Apple releases multiple iPhones every year, offering folks choice in terms of size and features. In 2024, the iPhone 15 lineup includes four distinct models.

The regular iPhone 15 and iPhone 15 Plus are great for those who don’t need a telephoto lens and don’t care about the Action button or the 1TB of storage. But anyone who wants a more “pro” experience has the iPhone 15 Pro and iPhone 15 Pro Max.

Read more