logo

Helping a mobile malware fraud victim

ID: fc4ea43d-684b-56fd-890e-415109d7fd30

STIX ID: report--fc4ea43d-684b-56fd-890e-415109d7fd30

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-01-02

Date Updated: 2026-03-24

Author: Ken Munro

...
...

An investigation into a July–August 2023 mobile fraud revealed a malicious Android app, "PDF AI: Add-On," that abused Accessibility permissions to keylog, read SMS, block user actions, and display phishing overlays (including Barclays), enabling theft of banking credentials and ~£12,000 in fraudulent transfers detected on August 2; the device exhibited unusual behavior consistent with compromise, and while fund recovery seemed unlikely, the victim was refunded; the report concludes with practical guidance on app permissions, backups, and factory resets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.