Faketoken Malware Steals Banking Credentials from Uber-Like Apps
Recently, Kaspersky was able to identify a new version of a malware in several apps like Uber and has advised users to be careful of another mobile banking Trojan called Faketoken. This threat has already existed before and now it seems like cyber criminals have modified it to steal credentials from nu-taxis, traffic ticket paying apps, as well as flight and hotel room booking.
This new version of Faketoken malware currently targets taxi-like apps such as Uber which is one of the most popular services under this category, according to Kaspersky Lab. Its previous version has the ability to steal 2FA codes by intercepting text messages but its new version is distributed via bulk SMS messages.
As stated by the research team at Kaspersky Lab, a vast number of different services are being offered to users like taxi services or ride-sharing because of the growing trend of mobile apps. Since some of these apps require users’ confidential financial data and bank card information which are all stored on the application, these apps have become potential targets for cyber criminals.
Another dangerous functionality of this mobile banking Trojan is its ability to track other mobile applications. When a user opens a particular app, the malware modifies the app’s interface and runs a fake phishing window instead to trick users into providing their bank account details which can end up getting stolen. Take note that this malware copies the app’s interface containing similar color schemes and logos that creates a completely invisible overlay which makes it almost identical to the original app.
During its attack, the malware asks its users to download some images and once they do, that’s when the malware gets installed and hides its icon to secretly alter the overlay of banking and other applications installed on the Android device. It’s hard to escape its attack since it can perform its trick on all kinds of apps, be it from Google Play Store or Android Pay. Once the user’s credentials are stolen, the crooks gets hold of them and use them illegally such as bank fraud or identity theft.
Aside from its ability to steal banking information and track other mobile applications, the malware can also monitor and track SMS messages and phone calls. Infected smart phones face SMS message redirections to obtain passwords and other information and the threat of having their calls recorded – all of which could be used and sent off for bad purposes.
It is common knowledge that the banking industry is one of the main targets of malware and still remains so. However, adding the taxi or ride-sharing services is definitely new which could only mean that cyber crooks are working double time to expand their domains and spread their range to other areas. So it is the responsibility of application developers to enhance their security in order to protect their users from harmful threats.
According to Viktor Chebyshev, a security exoert from KAspersky Lab, “Previous response involved the implementation of security technologies in apps that significantly reduced the risk of theft of critical financial data. Perhaps now it is time for other services that are working with financial data to follow suit.”
As of now, Faketoken only has its grasp to Russian and ex-Soviet countries’ users, but that’s bound to change if users aren’t careful enough and if app developers won’t make any efforts to prevent Faketoken’s attacks and other similar banking Trojan.
“To this day we still have not registered a large number of attacks with the Faketoken sample, and we are inclined to believe that this is one of its test versions. According to the list of attacked applications, the Russian UI of the overlays, and the Russian language in the code, Faketoken.q is focused on attacking users from Russia and CIS countries,” Kaspersky researchers stated.
Besides increasing your device’s activities, security experts suggested that users must avoid installing applications from shady third party app sources and only install apps from Google Play Store and other trusted app sources. In addition, users shouldn’t download any attachments from unknown and suspicious sources.
There’s one particular application that shares the same ability with Faketoken malware, the Sms tracker, which can also track and monitor SMS messages and phone call. But unlike Faketoken, Sms tracker is NOT a malicious software nor does it steal any kind of information. Best SMS tracker is a legitimate and useful application that lets users track and monitor SMS, call log, GPS locations, photos and social media activity. This app is mostly ideal for parents, employers and for those people who are in a relationship that wants to keep track of their kids, employees or partners’ device activities.













