April 02, 2024
This nasty Android banking trojan lets hackers completely hijack your phone — how to stay safe
Hackers have a new tool in their Arsenal as one of the most advanced Android banking trojans has just been upgraded with new features that let it remotely control infected devices. First discovered by the security firm ThreatFabric back in 2021, Vultur was one of the first banking trojans that could record the screen of infected Android smartphones. In the years since, its creators have updated this Android malware to make it even more dangerous. As reported by SecurityWeek , new technical features have been added to Vultur and the malware is now even better at evading detection too. While it was initially distributed using malicious apps on the Google Play Store, security researchers at the NCC Group recently observed a brand new campaign which uses a novel distribution method to trick unsuspecting users into installing this malware on the best Android phones . Here’s everything you need to know about the Vultur banking trojan along with some tips and tricks on how you can avoid having your phone hijacked by hackers. Instead of infecting users through malicious apps, this new campaign uses a hybrid attack which starts with a text message and is then followed by a phone call and yet another text message. In its report , NCC Group’s security researchers explain that this hybrid attack begins with a text message that instructs potential victims to call a number if they didn’t authorize a large transaction from their bank account. While this transaction never actually took place, the message creates a sense of urgency which might be enough to trick users into calling the number. If they do call to inquire about the large transaction, a second text message is sent during the call. It contains a link to a trojanized version of a McAfee Security app which they are coerced into installing on their smartphone. The app itself appears legitimate at first glance but it actually contains the Brunhilda dropper which is then used to download the Vultur banking trojan. Upgrade your life with a daily dose of the biggest tech news, lifestyle hacks and our curated analysis. Be the first to know about cutting-edge gadgets and the hottest deals. The malware is downloaded in three separate payloads which are combined on the targeted Android smartphone. Once installed, the hackers behind this campaign gain complete control over an infected device. The Vultur banking trojan was dangerous enough when it was first observed but now, it has even more features that hackers can use in their attacks. For instance, the malware can download, upload, delete, install and find files on an infected Android smartphone but it can also prevent apps from running in the first place. Likewise, it can display a custom notification in the status bar and even disable Keyguard which allows it to bypass your lock screen. However, the new remote control capabilities are by far the most interesting. Although Vultur still uses AlphaVNC and ngrok for remote access functionality like it did back in 2021, a hacker can now send commands to an infected smartphone to perform scrolls, swipe gestures, clicks, mute/unmute the device’s audio and more. Just like with other Android malware strains, Vultur abuses the operating system’s Accessibility Services to gain even more control over an infected device. The cybercriminals behind this banking trojan are also leveraging Google’s own Firebase Cloud Messaging ( FCM ) service to send messages from a command and control ( C2 ) server they control to an infected phone. Normally, hackers need to have an ongoing connection with an infected device in order to control it. By using FCM though, they can send a command even if their connection to the device is lost. AlphaVNC and ngrok still require an ongoing remote connection but this new feature adds more flexibility while making things easier for hackers that have deployed this malware in their attacks. The newly added file manager functionality also gives hackers more control over infected Android smartphones since they can take existing files off of the device as well as upload new ones to use in additional attacks. Although I would usually tell you to steer clear from Android apps with poor ratings and to avoid sideloading apps if you want to stay safe from malware, this campaign is a bit different. It’s more like a phishing attack since it starts with an urgent message from an unknown sender. In cases like this, you need to keep a level head and avoid letting your emotions get the best of you. Instead of responding to the message immediately or even at all, what you should do first is to check your bank accounts to see if this large transaction actually happened. This would reveal that it didn’t and you could safely ignore the message. At the same time, you never want to call hackers back on the phone when they provide you with a number, either by text or email. Automated email security checks now prevent many of their messages from getting through which is why hackers have begun trying to trick users into calling them. It’s a lot easier to convince someone to do something they may not necessarily want to do when you’re talking with them on the phone. To protect yourself from trojanized apps like the one used in this attack, you should ensure that Google Play Protect is installed and enabled on your Android smartphone. These days though, most Android phones come with it pre-installed. For extra protection, you should also consider using one of the best Android antivirus apps as they’re updated more frequently and many of them include extra security features like a VPN or a password manager . As Google and other companies get better at fending off attacks like this one, hackers will continue to devise new ways to trick you into installing malware on your smartphone. This is why you need to be extra careful when installing any new app while avoiding ones you have to manually install at all costs.
Related Stories
Latest News
Top news around the world
Academy Awards

‘Oppenheimer’ Reigns at Oscars With Seven Wins, Including Best Picture and Director

Get the latest news about the 2024 Oscars, including nominations, winners, predictions and red carpet fashion at 96th Academy Awards

Around the World

Celebrity News

> Latest News in Media

Watch It
JoJo Siwa Reveals She Spent $50k on This Cosmetic Procedure
April 08, 2024
tilULujKDIA
Gypsy Rose Blanchard Files for Divorce from Ryan Anderson
April 08, 2024
kjqE93AL4AM
Bachelor Nation’s Trista Sutter Shares Update on Husband’s Battle With Lyme Disease | E! News
April 08, 2024
mNBxwEpFN4Y
Alan Tudyk Does All His Disney Voices
April 08, 2024
fkqBY4E9QPs
Bob Iger responds to critics who call Disney "too woke"
April 06, 2024
loZMrwBYVbI
Kirsten Dunst recites a classic cheer from 'Bring it On'
April 06, 2024
VHAca3r0t-k
Dr. Paul Nassif Offers Up Plastic Surgery Warning for Gypsy Rose Blanchard | TMZ
April 09, 2024
cXIyPm8mKGY
Reba McEntire Laughs at Joy Behar's Suggestion 'Jolene' is Anti-Feminist | TMZ TV
April 08, 2024
11Cyp1sH14I
NeNe Leakes Says She's Okay with Cheating If It's Done Respectfully | TMZ TV
April 08, 2024
IsjAeJFgwhk
Ben Affleck and Jennifer Lopez’s wedding was 20 years in the making
April 08, 2024
BU8hh19xtzA
Bianca Censori wears completely sheer tube dress and knee-high stockings for Kanye West outing
April 08, 2024
IkbdMacAuhU
Kelsea Ballerini tells trolls to ‘shut up’ about pantsless CMT Music Awards 2024 performance #shorts
April 08, 2024
G4OSTYyXcOc
TV Schedule
Late Night Show
Watch the latest shows of U.S. top comedians

Sports

Latest sport results, news, videos, interviews and comments
Latest Events
08
Apr
ITALY: Serie A
Udinese - Inter Milan
07
Apr
ENGLAND: Premier League
Manchester United - Liverpool
07
Apr
ENGLAND: Premier League
Tottenham Hotspur - Nottingham Forest
07
Apr
ITALY: Serie A
Juventus - Fiorentina
07
Apr
ENGLAND: Premier League
Sheffield United - Chelsea
07
Apr
ITALY: Serie A
Monza - Napoli
07
Apr
GERMANY: Bundesliga
Wolfsburg - Borussia Monchengladbach
07
Apr
ITALY: Serie A
Verona - Genoa
07
Apr
ITALY: Serie A
Cagliari - Atalanta
07
Apr
GERMANY: Bundesliga
Hoffenheim - Augsburg
07
Apr
ITALY: Serie A
Frosinone - Bologna
06
Apr
GERMANY: Bundesliga
Heidenheim - Bayern Munich
06
Apr
GERMANY: Bundesliga
Borussia Dortmund - Stuttgart
06
Apr
ENGLAND: Premier League
Brighton - Arsenal
06
Apr
ITALY: Serie A
Roma - Lazio
06
Apr
ENGLAND: Premier League
Crystal Palace - Manchester City
06
Apr
ITALY: Serie A
AC Milan - Lecce
04
Apr
ENGLAND: Premier League
Chelsea - Manchester United
04
Apr
ENGLAND: Premier League
Liverpool - Sheffield United
03
Apr
ENGLAND: Premier League
Arsenal - Luton
03
Apr
ENGLAND: Premier League
Manchester City - Aston Villa
02
Apr
ENGLAND: Premier League
West Ham United - Tottenham Hotspur
01
Apr
SPAIN: La Liga
Villarreal - Atletico Madrid
01
Apr
ITALY: Serie A
Lecce - Roma
01
Apr
ITALY: Serie A
Inter Milan - Empoli
31
Mar
ENGLAND: Premier League
Manchester City - Arsenal
31
Mar
SPAIN: La Liga
Real Madrid - Athletic Bilbao
31
Mar
ENGLAND: Premier League
Liverpool - Brighton
30
Mar
SPAIN: La Liga
Barcelona - Las Palmas
30
Mar
ENGLAND: Premier League
Brentford - Manchester United
30
Mar
ITALY: Serie A
Fiorentina - AC Milan
Find us on Instagram
at @feedimo to stay up to date with the latest.
Featured Video You Might Like
zWJ3MxW_HWA L1eLanNeZKg i1XRgbyUtOo -g9Qziqbif8 0vmRhiLHE2U JFCZUoa6MYE UfN5PCF5EUo 2PV55f3-UAg W3y9zuI_F64 -7qCxIccihU pQ9gcOoH9R8 g5MRDEXRk4k
Copyright © 2020 Feedimo. All Rights Reserved.