Android malware distributed in Mexico uses Covid-19 to steal financial credentials
ID: db3c9188-b464-5dd0-9b56-d5fb172290e2
STIX ID: report--db3c9188-b464-5dd0-9b56-d5fb172290e2
Feed Name: McAfee Labs Blog
Threat Score
McAfee analysts identify Android/Banker.BT, a Mexico-targeted mobile banking trojan distributed via phishing/smishing and fake bank/security apps; it prompts users to enter credentials, requests SMS permissions, exfiltrates login data and SMS messages to a C2 (sent in URL parameters), and includes four SHA256 IoCs — the malware appears locally developed and early-stage but capable of full account takeover via stolen credentials and OTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
