Skip to main content

Russian Android malware infects millions of phones, drains bank accounts

Can cops and hackers track your phone
blurAZ/Shutterstock
Hackers used mobile malware to steal hundreds of thousands of dollars from bank customers. That’s according to Reuters, which reported on May 22 that cybercriminals tricked Russian users of Google’s Android operating system into downloading malicious apps.

The group of 16 Russian hackers, operating under the code name “Cron” after the malware they used, disguised the malware as fake banking applications and pornography web clients. When Android users in Russia searched online, the search engine results would suggest the fake apps.

The core members of the group were arrested on November 22 last year, before they could mount attacks outside Russia. But according to Group-IB, the cyber security firm investigating the attack with the Russian Interior Ministry, the Cron group infected more than a million smartphones in Russia at a rate of 3,500 devices a day.

“Cron’s success was due to two main factors,” Dmitry Volkov, head of investigations at Group-IB, said in a statement. “First, the large-scale use of partner programs to distribute the malware in different ways. Second, the automation of many (mobile) functions which allowed them to carry out the thefts without direct involvement.”

They targeted customers of Sberbank, Alfa Bank, and online payments company Qiwi, exploiting SMS text message transfer services. The group sent texts from infected devices instructing the banks to transfer money to the hackers’ accounts — up to $120 to one of the 6,000 fraudulent accounts. And they intercepted the transaction confirmation codes, preventing the victims from receiving a messages notifying them about the transaction.

They’d planned to go after large European banks including French lenders Credit Agricole, BNP Paribas, and Societe General, according to Group-IB.

Cron malware, which was first detected in mid-2015, had been in use for more than a year before the arrests. The Russian hackers rented a “Tiny.z,” a piece of malware designed to attack checking accounts systems, for $2,000 a month in June 2016, and adapted it to target European banks in Britain, Germany, France, the United States, and Turkey, among other countries.

Lukas Stefanko, a malware researcher at cyber security firm ESET in Slovakia, told Reuters that the exploit highlighted the dangers of SMS messages in mobile banking.

“It’s becoming popular among developing nations or in the countryside where access to conventional banking is difficult for people,” he said. “For them it is quick, easy, and they don’t need to visit a bank … But security always has to outweigh consumer convenience.”

Editors' Recommendations

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
How to reset default apps on an Android phone or tablet
Someone holding a Google Pixel 5. The screen is on and shows the Home Screen with an app folder open.

One of the best things about owning an Android phone is being able to change your default apps. If you've ever opened a file or an internet link with a certain app, and you chose Always when prompted, then that type of file will be opened with that app every time, saving you from tapping that app every time, and reclaiming some precious time. But what happens if you're the indecisive type or if you suddenly find a better app you'd like to use as your default? It's easy enough to go change.
Stock Android
“Stock Android” refers to any basic Android device that is similar to Google’s version. If you’re the owner of a phone running Stock Android — like the Google Pixel 5, the Xiaomi Mi A3, or the Motorola One Vision, here’s how to reset your app preferences.

Resetting preferences for a single app

Read more
The best iPhone and Android apps for Black History Month 2024
best iPhone and Android apps for Black History Month.

February is celebrated as Black History Month to honor Black Americans' remarkable achievements and contributions. The theme for this year is "African Americans and the Arts," which shines a light on the impact of African Americans in different artistic fields, such as cultural expression, visual and performing arts, fashion, literature, and more.

In this regard, we present a list of popular iOS and Android apps developed by Black-owned businesses and cover various topics such as finance, entertainment, wellness, and more. These apps run on all the latest smartphones, including the Samsung Galaxy S24 Ultra and iPhone 15 Pro.
Calendly

Read more
How to save text messages on iPhone and Android
iMessage on an iPhone.

We receive a lot of important information via text. Whether it’s a date you need to set or important work-related info, you might find yourself wanting to save a text message. Modern smartphones all offer a way to back up your core data and transfer it to another device. However, transfers sometimes don’t include your text messages unless you save them ahead of time or are transferring across the same mobile operating system.

Here's how to save your text messages in Android and iOS.
How to save your text messages on iPhone
There are multiple ways to backup your iPhone text messages. Here are the easiest.
How to make iPhone text message backups using iExplorer
The most universal method of saving your iPhone text messages is via the iExplorer program.

Read more