February 20,2025
6 mins
A sophisticated malware campaign, dubbed “FinStealer,” is actively targeting customers of a leading Indian bank through fraudulent mobile applications. Security researchers at CYFIRMA have identified the malware as Trojan.rewardsteal/joxpk, which is designed to steal banking credentials and personal information from unsuspecting users.
Let’s know more about this.
Keep reading?
Table of Contents!
How the Malware Operates Security Risks and Recommendations Staying Safe from FinStealer How to Spot Login Credential Fraud How to Protect Your Login Credentials |
The attack is being carried out through a suspicious website, motocharge[.]online, which distributes fake banking apps designed to look like legitimate ones. Once installed, the malware begins its stealthy operation, extracting sensitive user data while remaining undetected.
CYFIRMA analysts found that FinStealer is built using Kotlin and employs advanced evasion techniques, including:
The malware communicates with its C2 infrastructure through a Telegram bot, using the API key: 7754264825:AAEqSBGNuEbuMqnWFqN7E_SvhS5sy_IFjEE. The stolen data includes:
Related Read: Top 7 Tips to Safeguard Your Digital Identity Like a Pro!
Researchers also discovered a critical vulnerability (CVE-2011-2688) in the C2 server, which allows SQL injection attacks via the mysql/mysql-auth.pl script in the mod_authnz_external module.
To protect against this ongoing threat, CYFIRMA recommends:
The below-mentioned YARA rule might help in identifying malware:
With the campaign still active, researchers continue to monitor new variants and attack vectors. Meanwhile, users are strongly advised to download banking apps only from official sources and verify app authenticity before installation to avoid falling victim to this stealthy malware attack.
Read More: Malware vs. Viruses: Learn the Differences and Protection Tips
Login credential fraud is a critical danger in today’s digital landscape. Cybercriminals use malware and malicious assaults to steal your login credentials, doubtlessly leading to identity theft and credit card fraud.
Here are some key signs to watch for:
Utilize robust anti-malware solutions and mobile malware protection to guard your accounts.
Can Your Device Handle A Malware Attack?
AVP Suite stops threats before they strike, protecting data and devices from malware Try AVP Suite for Free! |
Maintaining your login credentials is crucial for safeguarding your personal data and preventing identity theft. Follow these steps to build a robust defense against malicious attacks and data breaches.
These proactive measures can significantly boost your identity theft protection and keep your login credentials safe. Embrace these practices for stronger data security and peace of mind in today’s digital world.
Want to know more about digital identity and login credential protection?
Visit the AVP Suite for enhanced security!
A sophisticated malware campaign, dubbed “FinStealer,” is actively targeting customers of a leading Indian bank through fraudulent mobile applications. Security researchers at CYFIRMA have identified the malware as Trojan.rewardsteal/joxpk, which is designed to steal banking credentials and personal information from unsuspecting users.
Let’s know more about this.
Keep reading?
The attack is being carried out through a suspicious website, motocharge[.]online, which distributes fake banking apps designed to look like legitimate ones. Once installed, the malware begins its stealthy operation, extracting sensitive user data while remaining undetected.
CYFIRMA analysts found that FinStealer is built using Kotlin and employs advanced evasion techniques, including:
The malware communicates with its C2 infrastructure through a Telegram bot, using the API key: 7754264825:AAEqSBGNuEbuMqnWFqN7E_SvhS5sy_IFjEE. The stolen data includes:
Related Read: Top 7 Tips to Safeguard Your Digital Identity Like a Pro!
Researchers also discovered a critical vulnerability (CVE-2011-2688) in the C2 server, which allows SQL injection attacks via the mysql/mysql-auth.pl script in the mod_authnz_external module.
To protect against this ongoing threat, CYFIRMA recommends:
The below-mentioned YARA rule might help in identifying malware:
With the campaign still active, researchers continue to monitor new variants and attack vectors. Meanwhile, users are strongly advised to download banking apps only from official sources and verify app authenticity before installation to avoid falling victim to this stealthy malware attack.
Read More: Malware vs. Viruses: Learn the Differences and Protection Tips
Login credential fraud is a critical danger in today’s digital landscape. Cybercriminals use malware and malicious assaults to steal your login credentials, doubtlessly leading to identity theft and credit card fraud.
Here are some key signs to watch for:
Utilize robust anti-malware solutions and mobile malware protection to guard your accounts.
AVP Suite stops threats before they strike, protecting data and devices from malware
Try AVP Suite for Free!Maintaining your login credentials is crucial for safeguarding your personal data and preventing identity theft. Follow these steps to build a robust defense against malicious attacks and data breaches.
These proactive measures can significantly boost your identity theft protection and keep your login credentials safe. Embrace these practices for stronger data security and peace of mind in today’s digital world.
Want to know more about digital identity and login credential protection?
Visit the AVP Suite for enhanced security!