TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud

Image
Cybersecurity researchers have uncovered a new variant of an Android banking trojan called TrickMo that comes packed with new capabilities to evade analysis and display fake login screens to capture victims' banking credentials. "The mechanisms include using malformed ZIP files in combination with JSONPacker," Cleafy security researchers Michele Roviello and Alessandro Strino  said . "In addition, the application is installed through a dropper app that shares the same anti-analysis mechanisms." "These features are designed to evade detection and hinder cybersecurity professionals' efforts to analyze and mitigate the malware." TrickMo, first caught in the wild by CERT-Bund in September 2019, has a  history  of targeting Android devices, particularly targeting users in Germany to siphon one-time passwords (OTPs) and other two-factor authentication (2FA) codes to facilitate financial fraud. The mobile-focused malware is assessed to be the work of the ...

Payment gateway data breach affects 1.7 million credit card owners

 

Payment gateway provider Slim CD has disclosed a data breach that compromised credit card and personal data belonging to almost 1.7 million individuals.

In the notification sent to impacted clients, the company says that hackers had access to its network for nearly a year, between August 2023 and June 2024.

Slim CD is a provider of payment processing solutions that enables businesses to access electronic and card payments via web-based terminals, mobile, or desktop apps.

The firm first detected suspicious activity on its systems this year on June 15. During the investigation, the company discovered that hackers had gained access to its network since August 17, 2023. 

“The investigation identified unauthorized system access between August 17, 2023, and June 15, 2024,” reads the notification to impacted individuals.

However, Slim CD says that the threat actor viewed or obtained access to credit card information this year for two days, between June 14th and 15th

 "That access may have enabled an unauthorized actor to view or obtain certain credit card information between June 14, 2024, and June 15, 2024,” Slim CD says in the data breach notification.

The types of data that may have been accessed by the unauthorized part include:

  • Full name
  • Physical address
  • Credit card number
  • Payment card expiration date

Though the exposed information is not enough to allow cybercriminals to perform fraudulent transactions, since the card verification number (CVV) is missing, a risk of credit card fraud still exists.

Slim CD says it has taken measures to strengthen its security to prevent similar incidents in the future.

At the same time, it advises the notice recipients to remain vigilant for signs of fraud and identity fraud attempts and report suspicious activity to the card issuer as soon as possible.

No free-of-charge identity theft protection services were offered to the affected individuals.

Slim CD offers payment processing services to various industries, including retail, hospitality, and restaurants, but individuals receiving the breach notifications are likely unfamiliar with it as they never directly interacted with the company

Comments

Popular posts from this blog

TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud

Meta fixes easily bypassed WhatsApp ‘View Once’ privacy feature