February 20,2025
6 mins
The “FinStealer” is a sophisticated malware campaign that targets customers of a leading Indian bank via fraudulent mobile apps. The security researchers at CYFIRMA identified the malware as Trojan.rewardsteal/joxpk, intended to steal banking credentials and personal information from unsuspecting users.
Let’s know more about this.
Keep reading?
Table of Contents!
How the Malware Operates Security Risks and Recommendations Staying Safe from FinStealer How to Spot Login Credential Fraud How to Protect Your Login Credentials |
The site, under a pretty suspicious domain, is called Motocharge [.]online and distributes fake banking apps designed similarly to the real ones.
Once installed, the malicious software starts performing its operations without the user’s knowledge, collecting sensitive information from the users.
CYFIRMA analysts found that FinStealer is built using Kotlin and employs advanced evasion techniques, including:
The malware communicates with its C2 infrastructure through a Telegram bot, using the API key: 7754264825:AAEqSBGNuEbuMqnWFqN7E_SvhS5sy_IFjEE. The stolen data includes:
Related Read: Top 7 Tips to Safeguard Your Digital Identity Like a Pro!
A critical vulnerability (CVE-2011-2688) was also discovered on the C2 server that permits SQL injection attacks through the mysql/mysql-auth.pl script in the mod_authnz_external module.
To protect against this persistent threat, CYFIRMA recommends the following:
The below-mentioned YARA rule might help in identifying malware:
The campaign continues; therefore, researchers keep watching for new variants and attack vectors. Users are advised to download banking apps from only legitimate sources and verify them upon installation to avoid falling prey to this shadowy malware attack.
Read More: Malware vs. Viruses: Learn the Differences and Protection Tips
Login credential fraud is a critical danger in today’s digital landscape. Cybercriminals use malware and malicious assaults to steal your login credentials, doubtlessly leading to identity theft and credit card fraud.
Here are some key signs to watch for:
Utilize robust anti-malware solutions and mobile malware protection to guard your accounts.
Can Your Device Handle A Malware Attack?
AVP Suite stops threats before they strike, protecting data and devices from malware Try AVP Suite for Free! |
Your login information is essential to avoiding identity theft and preserving your personal data.
Follow these steps to build a robust defense against malicious attacks and data breaches:
Following these security measures rigorously can significantly increase your protection from identity theft and secure your login credentials. Embrace these practices for stronger data security and peace of mind in today’s digital world.
Want to know more about digital identity and login credential protection?
Visit the AVP Suite for enhanced security!
The “FinStealer” is a sophisticated malware campaign that targets customers of a leading Indian bank via fraudulent mobile apps. The security researchers at CYFIRMA identified the malware as Trojan.rewardsteal/joxpk, intended to steal banking credentials and personal information from unsuspecting users.
Let’s know more about this.
Keep reading?
The site, under a pretty suspicious domain, is called Motocharge [.]online and distributes fake banking apps designed similarly to the real ones.
Once installed, the malicious software starts performing its operations without the user’s knowledge, collecting sensitive information from the users.
CYFIRMA analysts found that FinStealer is built using Kotlin and employs advanced evasion techniques, including:
The malware communicates with its C2 infrastructure through a Telegram bot, using the API key: 7754264825:AAEqSBGNuEbuMqnWFqN7E_SvhS5sy_IFjEE. The stolen data includes:
Related Read: Top 7 Tips to Safeguard Your Digital Identity Like a Pro!
A critical vulnerability (CVE-2011-2688) was also discovered on the C2 server that permits SQL injection attacks through the mysql/mysql-auth.pl script in the mod_authnz_external module.
To protect against this persistent threat, CYFIRMA recommends the following:
The below-mentioned YARA rule might help in identifying malware:
The campaign continues; therefore, researchers keep watching for new variants and attack vectors. Users are advised to download banking apps from only legitimate sources and verify them upon installation to avoid falling prey to this shadowy malware attack.
Read More: Malware vs. Viruses: Learn the Differences and Protection Tips
Login credential fraud is a critical danger in today’s digital landscape. Cybercriminals use malware and malicious assaults to steal your login credentials, doubtlessly leading to identity theft and credit card fraud.
Here are some key signs to watch for:
Utilize robust anti-malware solutions and mobile malware protection to guard your accounts.
AVP Suite stops threats before they strike, protecting data and devices from malware
Try AVP Suite for Free!Your login information is essential to avoiding identity theft and preserving your personal data.
Follow these steps to build a robust defense against malicious attacks and data breaches:
Following these security measures rigorously can significantly increase your protection from identity theft and secure your login credentials. Embrace these practices for stronger data security and peace of mind in today’s digital world.
Want to know more about digital identity and login credential protection?
Visit the AVP Suite for enhanced security!