'TeaBot' malware ,data-stealing app found in Google Play
By MYBRANDBOOK
A newly found dangerous Android malware found In Google play store, it is capable of stealing your data like passwords and text messages, has been discovered in Google Play and downloaded thousands of times.
Initially, TeaBot has been distributed through smishing campaigns using a predefined list of lures, such as TeaTV, VLC Media Player, DHL and UPS and others, according to online fraud management and prevention solution provider Cleafy.
The TeaBot banking trojan, also known as Anatsa and Toddler, was first observed in May 2021 targeting European banks by stealing two-factor authentication codes sent by text message.
In the last months, we detected a major increase of targets which now count more than 400 applications, including banks, crypto exchanges/wallets and digital insurance, and new countries such as Russia, Hong Kong, and the United States," the researchers informed.
Cleafy says that while the malware was previously distributed through SMS-based phishing campaigns using a number of common apps as lures, such as TeaTV, VLC Media Player and shipping apps like DHL and UPS, its researchers say the malicious Google Play app was acting as a “dropper” to deliver TeaBot by way of a fake in-app update. Droppers are apps that appear legitimate, but in fact deliver a second-stage malicious payload.
During the last months, TeaBot has also started supporting new languages, such as Russian, Slovak and Mandarin Chinese, useful for displaying custom messages during the installation phases.
On February 21, the Cleafy Threat Intelligence and Incident Response (TIR) team discovered an application published on the official Google Play Store, which was acting as a dropper application delivering TeaBot with a fake update procedure.
The app, “QR Code & Barcode – Scanner,” since removed, managed to pull in more than 10,000 downloads by the time it was discovered. But because the app offers the promised functionality, nearly all of the app’s reviews are positive.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
SECUREYE SERVICES PVT. LTD.
DRUVA SOFTWARE PVT. LTD.
WIPRO LTD.
INFOSYS TECHNOLOGIES PVT. LTD.
ICONS OF INDIA : RAJIV MEMANI
As Chair of the EY Global Emerging Markets Committee, Rajiv connects e...
Icons Of India : NIKHIL RATHI
Co-founder & CEO of Web Werks, a global leader in Data Centers and Clo...
ICONS OF INDIA : SANJAY NAYAR
Sanjay Nayar is a senior finance professional in the Indian private in...
EESL - Energy Efficiency Services Limited
EESL is uniquely positioned in India’s energy sector to address ener...
PFC - Power Finance Corporation Ltd
PFC is a leading financial institution in India specializing in power ...
DRDO - Defence Research and Development Organisation
DRDO responsible for the development of technology for use by the mili...
Indian Tech Talent Excelling The Tech World - ARVIND KRISHNA, CEO – IBM
Arvind Krishna, an Indian-American business executive, serves as the C...
Indian Tech Talent Excelling The Tech World - Aneel Bhusri, CEO, Workday
Aneel Bhusri, Co-Founder and Executive Chair at Workday, has been a le...
Indian Tech Talent Excelling The Tech World - JAYASHREE ULLAL, President and CEO - Arista Network
Jayshree V. Ullal is a British-American billionaire businesswoman, ser...