Advertisement

BlackRock: A new Android malware could target 337 apps including Instagram, Gmail, Twitter others

Reportedly, BlacRock isn't on the Play Store as of now, but is getting to devices by being offered as a fake Google Update on third-party stores.

Advertisement
FP Trending|Jul 20, 2020, 15:50:32 IST

A new Android malware has recently been reported, which is apparently equipped with data theft capabilities that allow it to target 337 Android applications. The malware is named BlackRock and was first seen in May by mobile security firm ThreatFabric, according to a report by ZDNet.Reportedly, researchers say the malware was based on leaked source malware strain but was enhanced with more features, especially those that deal with theft of user passwords and credit card information. The report added that BlackRock works like most Android banking trojans but targets more apps than its predecessors.[caption id="attachment_8619561" align="alignnone" width="1280"]Representational Image. Creative credit: Nandini Yadav/tech2 Representational Image. Creative credit: Nandini Yadav/tech2[/caption]TomsGuide cited a ThreatFabric report that says that the source code was made public by its author around May 2019. The firm believes that BlackRock is the only banking Trojan currently using the source code.The report reveals that BlackRock steals credentials such as username and password from apps such as Amazon, Cash App, eBay, Gmail, Google Play, Hotmail, Instagram, Microsoft Outlook, myAT&T, Netflix, PayPal, Uber, and Yahoo Mail.Moreover, it steals credit-card numbers from apps like Facebook, Facebook Messenger, Google Hangouts, Grindr, Instagram, Kik, Periscope, Pinterest, PlayStation, Reddit, Skype, Snapchat, Telegram, TikTok, Tinder, Tumblr, Twitter, Viber, the Russian social network VK, WhatsApp, WeChat, and YouTube.According to PCMag, once it gets installed on a device, BlackRock monitors and detects when one of the legitimate apps it targets has been opened. At that point, an overlay pops up on the screen which looks like the legitimate app but is a fake. The user unknowingly enters their login and/or card details and BlackRock sends them off to a server while also returning the user to the legitimate app.The report, however, adds that for now, BlackRock isn't on the Play Store and is getting to devices by being offered as a fake Google Update on third-party stores.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Jul 20, 2020, 15:50:32 IST
Advertisement
Advertisement
Trending Stories

China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost

Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
Advertisement
Advertisement
Up Next