logo

Malicious iBanking application with new uninstall countermeasures

ID: 7af3d381-15fe-56ef-a92f-006cf4b23065

STIX ID: report--7af3d381-15fe-56ef-a92f-006cf4b23065

Feed Name: CERT Polska

Threat Score
72/100

Date Published: 2016-03-16

Date Updated: 2026-04-19

Author: Malgorzata Debska

...
...

This CERT report describes a campaign targeting Polish e-banking users in which attackers deliver webinject JavaScript that prompts victims to install a fake Trusteer Rapport Android app. The malicious app requests device-admin and extensive SMS/call/contacts permissions, intercepts and forwards OTPs and messages to attackers, resists uninstallation via persistent UI overlays and boot receivers, and is linked to observed file hashes; the report includes technical details and an ADB-based removal procedure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.