Beware: This Android Malware Can Steal Your Banking OTP

Advertisement
By Sumit Chakraborty | Updated: 5 January 2018 13:31 IST
Highlights
  • Malware is known as Android.banker.A9480
  • Android banking trojan steals login ID, password, SMS, contact lists
  • Not only banking apps, but cryptocurrency apps affected too

An Android malware is reportedly targeting over 232 banking apps including a few banks in India. The Trojan malware, named 'Android.banker.A9480', is designed to steal personal data from users, Quick Heal Security Labs reports. Similar to other banking malware, this one also sneaks into login data, SMS, contact lists and uploads them to a malicious server. Additionally, apart from the banking apps, this Trojan also targets cryptocurrency apps present on a user's phone.

Quick Heal lists the Indian banking apps that are targeted by the Android banking Trojan malware: Axis mobile, HDFC Bank MobileBanking, SBI Anywhere Personal, HDFC Bank MobileBanking LITE, iMobile by ICICI Bank, IDBI Bank GO Mobile+, Abhay by IDBI Bank Ltd, IDBI Bank GO Mobile, IDBI Bank mPassbook, Baroda mPassbook, Union Bank Mobile Banking, and Union Bank Commercial Clients.

ICICI Bank Says Mobile App Malware Not a Threat to Customers

Advertisement

Android.banker.A9480 malware gets circulated via a fake Flash Player app on third-party stores, Quick Heal said. The Flash Player app is a popular target for cybercriminals due to its prevalence. Once users download the malicious application, they get several prompts to activate administrative rights. The app sends numerous pop-ups to victims until the administrative privileges are activated, the report added.

Advertisement

Once the app is installed on a smartphone, the icon gets hidden when the user taps on it. The malicious app keeps working in the background while checking for one of the 232 banking apps. Further, if the app finds one of the targeted apps, it sends a fake notification that resembles the banking app. When users open the notification, they get a fake login window that is then used by the attackers to extract confidential data like login ID and password.

As per the blog posted by Quick Heal, the malware can process commands like sending and collecting SMS, upload contact list and location, display fake notification, accessibility and GPS permission, and more. Since the malware can intercept incoming and outgoing SMS from an infected smartphone, it is also able to bypass the OTP based two-factor authentication on the user's bank account.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Poco C81 Pro Moniker Confirmed via NBTC Certification Database
  2. Here's How Much the Samsung Galaxy S26 Series Might Cost in South Korea
  3. BenQ GW90TC Series Monitors With USB Type-C Connectivity Launched in India
  4. Google Adds Gemini-Powered Audio Summaries to Google Docs
  5. Tecno Pova Curve 2 5G Launches in India With Massive 8,000mAh Battery
  6. iPhone 17e Design, Colourways Seen in Concept Video With These Features
  7. Nvidia's GeForce Now App Brings Cloud Gaming to Your Amazon Fire TV Stick
  8. Google Chrome Finally Brings This Useful Desktop Feature to Android Users
  9. Here Are the Best Smartphones Under Rs. 25,000 in India
  10. Here's Everything That Was Announced at Sony's State of Play
  1. Google Chrome Brings Convenient Pinned Tabs Feature to Android Smartphone Owners
  2. Poco C81 Pro Appears on Thailand's NBTC Certification Database, Might Launch Soon
  3. Google Adds Gemini-Powered Audio Summaries to Google Docs
  4. BenQ GW90TC Series Monitors Launched in India With Up to 27-Inch Displays, USB Type-C Connectivity
  5. Nvidia Launches GeForce Now App for Select Amazon Fire TV Stick Models
  6. John Wick, God of War, Ghost of Yotei Legends: Everything Announced at State of Play
  7. Sony WH-1000XM6 Now Available in Sand Pink Colour Variant in India: Price, Availability, Features
  8. GST (Ghosts in Trouble) Out on Prime Video: Know Everything About This Kannada Comedy Drama Film
  9. I Am God OTT Release: Where to Watch the Kannada Romantic Thriller Online
  10. Kombuseevi Now Streaming on Tentkotta: Know Everything About This Tamil Film Online
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.