A particularly malicious banking trojan app for Android phones has just been exposed. This money-stealing scam app was targeting banking apps, online wallets, insurance apps, crypto wallets and more to steal data and passwords. Once retrieved, it would share the access with the hackers, who would steal the victim’s money. The scariest part about this online scaml is that the app was found on Google Play Store and was downloaded more than 10,000 times by innocent users. It is called ‘QR Code & Barcode – Scanner’ app and it has since been banned from the Google Play Store. Read on to know how this app banned by Google Play Store was operating.
The incident came to light after a report by Cleafy, an online fraud management and prevention firm, which highlighted that the trojan malware released by the app called TeaBot emerged at the beginning of 2021. The trojan was designed to steal the victim's “credentials and SMS messages”. The malware was very intelligent and was created in a way that it could hide in plain sight.
The app QR Code & Barcode - Scanner itself was designed to provide some benefits to users and thus became quite popular. And, since it worked as advertised, it had generally positive reviews. But although the app looked genuine, it was really an online scam app. Once downloaded, it would immediately request permission to download a second app called QR Code Scanner: Add-On. This app included multiple Teabot malware samples.
Once installed, the trojan would request permission for controlling the smartphone’s screen. Once it had that, it would fish out sensitive information such as login details, SMS messages and two-factor authentication codes. It also maliciously requested permissions to allow Teabot to record
Read more on tech.hindustantimes.com