• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - A new Android bot Trojan is here to steal your banking and financial data

A new Android bot Trojan is here to steal your banking and financial data

Claire by Claire
March 30, 2023 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

Keeping yourself safe online is increasingly challenging, and even reputable password managers can fall victim to hackers. Unscrupulous individuals who are too lazy to develop their own exploits from scratch can even use more convenient solutions such as MaaS (Malware-as-a-Service) to spread malware and infect other people’s devices. Security researchers have discovered a MaaS called Nexus that uses a Trojan to steal users’ banking and financial data from Android devices.

A new Android bot Trojan is here to steal your banking and financial data

Cybersecurity company Cleafy Sample data from underground forums were used to analyze Nexus’ modus operandi. The botnet, first discovered in March last year, allows unscrupulous actors to conduct ATO attacks for a fee of $3,000 per month. Nexus packages malicious Trojans into your Android with legitimate-looking, legitimate-looking apps inside suspicious third-party apps. Once a user’s device is infected, it immediately becomes part of a botnet controlled by hackers.

Recruitment ads posted by the Nexus botnet on underground forums. (Image source: Cleafy)

Nexus is a powerful malware capable of keylogging to record your passwords in various applications. It can also steal SMS-provided two-factor authentication (2FA) codes and information from the relatively secure Google Authenticator app, all without your knowledge. Malware can steal code to delete 2FA SMS, update automatically in the background, and distribute other malware. Because the victim device is part of a botnet, threat actors using Nexus can remotely monitor all bots (infected devices) and the data collected from them using a simple web panel. The interface reportedly allows customization of Nexus and supports remote injection of approximately 450 legitimate-looking banking application login pages to steal credentials.

Dashboard with detailed botnet information. (Image source: Cleafy)

Technically, Nexus is a mutation of the mid-2021 SOVA banking Trojan. Although Cleafy says the former appears to still be in beta development, SOVA’s source code has been stolen by Android botnet operators who also leveraged popular older MaaS. The stolen source code was exploited when running Nexus, and other malicious modules were added, such as ransomware, etc., which can lock users out of the device through AES (fortunately this part seems to be inactive at the moment).

Commands shared between Nexus and SOVA. (Image source: Cleafy)

Due to the Trojan-like nature of this malware, it can be difficult to detect on Android devices, but you may be aware of some obvious red flags and see unusual spikes in mobile data and Wi-Fi usage, which usually indicate that the malware is communicating with a hacked device or updating in the background.当设备未处于活动使用状态时,异常的电池消耗也可能是恶意软体引发后台活动的明显迹象。如果发现任何问题,建议在备份重要档案后将设备恢复原厂设置,或联系合格的网路安全专家。 To protect your Android device from dangerous malware like Nexus, always download apps from reputable sources, such as the Google Play Store. Additionally, make sure you’re running the latest available security updates and only grant apps authorizations that are critical to their operation. Apps like gallery or photo retouching apps shouldn’t need access to your call logs.

Source: KOCPC Chinese

Tags: AndroidInternet securityNEXUSTrojan horseVirus

Recent Posts

  • Meta Muse Lands on Mac: Personal AI Agent Begins Operating Your Files, Messages, and Calendar (Muse for Mac)
  • First oMLX performance results for M5 Ultra Mac Studio leak: prefill speed 3-4x faster than M3 Ultra, data taken down after exposure.
  • After the iPhone 17, the frame material was changed back to aluminum alloy. Is it better than titanium?
  • The iPhone 18 Pro series, Apple Watch Series 12, Apple Watch Ultra 4, and AirPods 5 are now on sale—a first look, with warm “Burgundy Red” and striking “Glacier Blue.”
  • The battery replacement cost for the iPhone 18 Pro / Pro Max has gone up again! Compared with 5 years ago, the increase has doubled.

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology