Subj : Beware - GoldDigger malware will drain your bank accounts without To : All From : TechnologyDaily Date : Sun Oct 08 2023 08:00:04 Beware - GoldDigger malware will drain your bank accounts without you even realizing Date: Sun, 08 Oct 2023 06:47:43 +0000 Description: A new and dangerous Android malware has emerged, stealing people's money and cryptocurrencies. FULL STORY ====================================================================== A dangerous new Android malware strain has been observed making the rounds, capable of stealing money from dozens of banking apps. This alarm was sounded by cybersecurity researchers Group-IB, which spotted the new campaign in June this year. In this campaign, unnamed threat actors were delivering a piece of malware called GoldDigger. The malware was being delivered via two separate apps - one impersonating a Vietnamese government portal, and another one impersonating an energy company. The attack vector itself wasnt discovered, but the researchers are making an educated guess that the attackers were reaching out to victims via social media channels, email messages, and other usual methods. Through these channels, they were navigating the victims to at least a dozen fake Google Play websites, where they were offered to download the apps. Accessibility and other red flags Once on the device, the apps would do the usual - ask for the Accessibility permissions. This is also probably the best way to spot a malicious app - if it demands excessive permissions. If the victim grants these permissions, GoldDigger will start by digging out sensitive user information, including passwords. It will then look for any of the 51 Vietnamese financial organizations' apps, e-wallet apps, and cryptocurrency wallet apps. If it finds any, GoldDigger will seek out and exfiltrate the login data for them, essentially granting the attackers unobstructed access to the victims money. One thing that makes GoldDigger unique, the researchers further explained, is Virbox Protector, a piece of integrated software used for obfuscation and encryption. While Virbox Protector itself is generally legitimate, here its being used for nefarious purposes and makes cybersecurity researchers jobs that much more difficult. There is no way of knowing exactly how many people fell for the trick and lost their money, but the warning is always the same - only download apps from legitimate sources and always be suspicious of links and attachments coming in through the mail. More from TechRadar Pro The FBI has taken down one of the biggest botnets in the world Here's a list of the best firewalls today These are the Best identity theft protection tools around ====================================================================== Link to news story: https://www.techradar.com/pro/security/beware-golddigger-malware-will-drain-yo ur-bank-accounts-without-you-even-realizing --- Mystic BBS v1.12 A47 (Linux/64) * Origin: tqwNet Technology News (1337:1/100) .