Malicious iBanking application with new uninstall countermeasures
ID: 7af3d381-15fe-56ef-a92f-006cf4b23065
STIX ID: report--7af3d381-15fe-56ef-a92f-006cf4b23065
Feed Name: CERT Polska
This CERT report describes a campaign targeting Polish e-banking users in which attackers deliver webinject JavaScript that prompts victims to install a fake Trusteer Rapport Android app. The malicious app requests device-admin and extensive SMS/call/contacts permissions, intercepts and forwards OTPs and messages to attackers, resists uninstallation via persistent UI overlays and boot receivers, and is linked to observed file hashes; the report includes technical details and an ADB-based removal procedure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
