Hackers Target Bank Customers with Fake App Updates via WebAPKs
Google Play Store has taken steps to safeguard users from malware by requiring a valid D-U-N-S number for new app submissions. However, cybercriminals have devised a new method to deceive users into installing malicious apps through WebAPKs, bypassing the Play Store’s security measures. Recently, security researchers discovered a campaign exploiting WebAPKs to trick victims. Hackers send fake messages, posing as banks, prompting users to update their banking apps. The links provided in these messages lead to websites that install malicious apps on users’ phones, enabling hackers to steal sensitive information, such as login credentials and 2FA codes, ultimately accessing and stealing money from their bank accounts.

The malicious apps utilizing WebAPK technology are challenging to track because they appear with different names and codes on each device. These cybercriminals exploit Android’s WebAPK technology to manipulate people into installing deceptive web apps through SMS messages, disguising them as mobile banking app updates. Once users click on the links, malicious apps are surreptitiously installed, impersonating legitimate banks and tricking users into providing their login credentials and 2FA tokens, thereby compromising their information.
To safeguard against such threats, it is essential to block websites that utilize WebAPK for phishing attacks. Furthermore, cybercriminals are employing specialized tools to deceive anti-fraud controls and gain access to compromised accounts for unauthorized transactions. To protect against these attacks, users are advised to download apps solely from official sources like the Google Play Store, avoid third-party app stores, refrain from opening links from text messages, and install antivirus and antimalware software on their smartphones. Being vigilant and cautious while interacting with app updates and links can significantly reduce the risk of falling victim to such deceptive schemes.
Comments
Post a Comment