Skip to main content

New Android banking malware steals your data with the snap of a selfie

pornhub app malware android
Image used with permission by copyright holder
Next time you take a selfie, it could be moments before a new piece of malware takes over your banking apps. But it can’t just be any old selfie — the authors of the malware are hoping you’ll hold up a government-issued ID in the photo, too.

The discovery of the new malware comes from security researchers at McAfee, who say that the malware disguises itself as either a video codec, Flash plug-in, or an app for Porn Tube. As you might notice, none of those apps should need to verify your identity with a government-issued ID, so if you have your common sense about you, this isn’t something you should fall for.

If you do happen to go as far as handing over your information to hackers, you’ve given them everything they need to steal your identity and you should probably take the proper precautions to get your identity back.

“In addition to requesting credit card information and second-factor authentication, the malicious application asks for a selfie with your identity document — very useful for a cybercriminal to confirm a victim’s identity and access not only banking accounts, but probably also even social networks,” said Carlos Castillo in a McAfee Labs blog post.

So how can you protect yourself against the threat? Well, first of all, you should avoid downloading shady third-party apps from any app store, and you should only be getting your apps from Google Play, as McAfee notes that the malware only seems to be appearing on apps downloaded from those third-party stores. If you do download an app that asks for personal information, make sure that personal information is something the app really needs to know — it’s very rare that you should need to hand over a photo of your ID.

Editors' Recommendations

Christian de Looper
Christian’s interest in technology began as a child in Australia, when he stumbled upon a computer at a garage sale that he…
If you have one of these apps on your Android phone, delete it immediately
The app drawer on the Google Pixel 8 Pro.

The NSO Group raised security alarms this week, and once again, it’s the devastatingly powerful Pegasus malware that was deployed in Jordan to spy on journalists and activists. While that’s a high-profile case that entailed Apple filing a lawsuit against NSO Group, there’s a whole world of seemingly innocuous Android apps that are harvesting sensitive data from an average person’s phone.
The security experts at ESET have spotted at least 12 Android apps, most of which are disguised as chat apps, that actually plant a Trojan on the phone and then steal details such as call logs and messages, remotely gain control of the camera, and even extract chat details from end-to-end encrypted platforms such as WhatsApp.
The apps in question are YohooTalk, TikTalk, Privee Talk, MeetMe, Nidus, GlowChat, Let’s Chat, Quick Chat, Rafaqat, Chit Chat, Hello Chat, and Wave Chat. Needless to say, if you have any of these apps installed on your devices, delete them immediately.
Notably, six of these apps were available on the Google Play Store, raising the risk stakes as users flock here, putting their faith in the security protocols put in place by Google. A remote access trojan (RAT) named Vajra Spy is at the center of these app's espionage activities.

A chat app doing serious damage

Read more
How to use Android Recovery Mode to fix your phone or tablet
Pixel 3 recovery mode

Here's an unfun scenario: You've got one of the best Android phones or tablets, but things aren't working right. Typical virus scans and other troubleshooting fixes aren't working. It is time to use recovery mode. This mode allows you to reboot your system and get a fresh start without any viruses or other issues that were potentially causing you trouble.

Unfortunately, there's no one standard way to get into Recovery Mode. In other words, Samsung Galaxy phones and HTC phones have different pathways into the modes. Luckily for you, however, we have the most complete guide to entering Recovery Mode and you should be able to figure out how to get in on just about any device using the steps below.

Read more
I used a new type of smartphone that could replace Android
Two phones running Apostrophy OS, sitting next to each other on a chair.

When you buy a phone today, your first decision is to decide which operating system you want: Android or iOS. We've seen other platforms come and go over the years, from Windows Phone to Palm OS, but Android and iOS remain your two sole choices in 2024.

One of the last things I saw at CES 2024 earlier this month was a smartphone operating system that's trying to be that third choice between Android and iOS. It's called Apostrophy OS (also referred to as AphyOS), and I got to play around with it while also chatting with Apostrophy CEO Steve Cistulli to learn about the could-be Android and iOS alternative.
What is Apostrophy OS?

Read more