Ghimob Malware Targeting Financial Android Apps, Offers Remote Access to Hacker: Kaspersky

Kaspersky says Ghimob spies on 153 mobile apps, mainly from banks, fintechs, cryptocurrencies and exchanges.

Advertisement
By Tasneem Akolawala | Updated: 10 November 2020 14:34 IST
Highlights
  • With Ghimob, the hacker can access the infected Android phones remotely
  • The Trojan is able to bypass screen lock as well
  • The hacker can complete fraud transactions via bank apps

Ghimob spies on112 apps from institutions in Brazil, 13 cryptocurrency app, Kaspersky says

New remote access Trojan called Ghimob has been targeting financial Android apps from banks, fintechs, exchanges and cryptocurrencies in Brazil, Paraguay, Peru, Portugal, Germany, Angola and Mozambique, security researchers at Kaspersky have discovered. This Trojan is said to have been deployed by a Brazil-based threat group Guildma - an actor part of the Tetrade family of banking Trojans - that was behind the recent Astaroth Windows malware as well. Once the Trojan is deployed on an Android smartphone, the hacker can access the infected device remotely, completing fraudulent transaction with the victim's smartphone without consent.

Kaspersky discovered the Ghimob Trojan (specifically, the Trojan-Banker.AndroidOS.Ghimob family of Trojan) while investigating another malware campaign. The Trojan is spread via email that pretends to be from a creditor and provides a link where the recipient could view more information, while
the app itself pretends to be Google Defender, Google Docs, WhatsApp Updater, etc. If the recipient falls for the scam and clicks on the link in an Android-based browser, the Ghimob APK installer gets downloaded on their smartphones.

Once infection is completed, the malware proceeds to send a message to the hacker. This includes the phone model, whether it has screen lock activated, and a list of all installed apps that the malware has as a target including version numbers. Kaspersky says Ghimob spies on 153 mobile apps, mainly from banks, fintechs, cryptocurrencies and exchanges. The report says that this includes about 112 apps from institutions in Brazil, 13 cryptocurrency apps from different countries, nine international payment systems, five bank apps in Germany, three bank apps in Portugal, two apps in Peru, two in Paraguay, and one app each from Angola and Mozambique as well.

Advertisement

With Ghimob, the hacker can access the infected device remotely, completing the fraudulent transaction with the victim's smartphone, so as to avoid machine identification, security measures implemented by financial institutions and all their antifraud behavioural systems. The hacker is also able to bypass screen lock, by recording it and later replaying it to unlock the device. “When the cybercriminal is ready to perform the transaction, they can insert a black screen as an overlay or open some website in full screen, so while the user looks at that screen, the criminal performs the transaction in the background by using the financial app running on the victim's smartphone that the user has opened or logged in to,” researchers at Kaspersky explain.

Advertisement

Ghimob tries to hide its presence by hiding the icon from the app drawer. The malware also blocks the user from uninstalling it, restarting or shutting down the phone. Kaspersky cautions, “Ghimob is the first Brazilian mobile banking trojan ready to expand and target financial institutions and their customers living in other countries. Our telemetry findings have confirmed victims in Brazil, but as we saw, the trojan is well prepared to steal credentials from banks, fintechs, exchanges, crypto-exchanges and credit cards from financial institutions operating in many countries, so it will naturally be an international expansion.”

Kaspersky warns financial institutions to be vary of Ghimob and improve their authentication processes, boost their anti-fraud technology and threat intel data.


Should the government explain why Chinese apps were banned? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Realme 16 Pro Series Will Launch in India
  2. OTT Releases This Week: Thamma, Mrs Deshpande, Raat Akeli Hai The Bansal Murders, and More
  3. Dreame's First Smartphone to Launch With These Specifications
  4. Oppo Reno 15 Pro Mini Tipped to Launch as First Compact Reno Smartphone
  5. Samsung Announces Exynos 2600 as World's First 2nm Chipset
  6. Instagram Will Now Restrict the Number of Hashtags You Can Use
  7. Ethirneechal Thodargiradhu Now Streaming on SunNXT: What You Need to Know
  8. Raju Weds Rambai Now Streaming Online: What You Need to Know
  9. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  1. Realme 16 Pro Series India Launch Date Announced: See Expected Specifications, Features
  2. Google Brings SynthID-Powered Deepfake AI Video Detection Tool to Gemini App
  3. Dreame E1 Phone to Reportedly Debut With 108-Megapixel Camera and 5,000mAh Battery: Expected Specifications
  4. Oppo Pad Air 5 Launch Date, Colourways, Storage Options Revealed: See Expected Specifications, Features
  5. Raju Weds Rambai Now Streaming Online: What You Need to Know
  6. The Fifty OTT Release: When and Where to Watch This High-Stakes Reality Show Online?
  7. Oppo Reno 15 Pro Mini Key Features Surface Online; Could Launch in Global Markets Soon
  8. Google's NotebookLM Updated With Data Tables, Export Support for Notes and Reports
  9. Samsung Galaxy Z Fold 8 Will Reportedly Launch With Telephoto and Ultrawide Camera Upgrades
  10. Instagram Announces a Five-Hashtag Limit for Reels and Posts to Improve Content Discovery
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.