Malware has always been the bane of everyone’s time online because it is the easiest backdoor for cybercriminals and thieves to gain entry. Google is usually vigilant about keeping the Play Store safe from malicious apps and making sure Android security updates are delivered in a timely manner, but attackers are always looking for ways to break through and steal victims’ money or personal data. Recently, a malware called “BingoMod” targeting Android devices was discovered, stealing all the victim’s financial data and then wiping the user’s device.

A new Android malware “BingoMod” is born, it wipes bank accounts and resets devices
There are many types of Android malware, but the latest malware that needs to be replaced is called “BingoMod”, foreign media Bleeping Computer existA report from researchers at cybersecurity firm Cleafy states, this malware uses a technique called Smishing to attack devices. Scams or SMS phishing deliver a web link containing malware to an unsuspecting victim’s device, in which case the victim installs the BingoMod app (version 1.5.1) under a false identity, often spoofing the app name, icon and security of mobile security tools such as AVG AntiVirus.

During installation, the app requests access to the device’s accessibility features, which it uses to steal credentials, capture screenshots, and intercept text messages, all of which are sent to unscrupulous individuals through a dedicated channel, giving them near-instant access to device functionality. According to the Cleafy report, the malware relies on the Android Media Projection API, which handles screenshot requests, to collect display information and help bad actors circumvent security measures such as multi-factor authentication.
The current main target is Italian equipment
BingoMod is currently using fake notifications and other overlays on the screen to hide attacks from victims while stealing money and data in the background. The app is believed to have originated in Romania, with possible contributions from developers from other parts of the world, and is currently targeting devices in Italy, with amounts stolen up to €15,000 per transaction. However, experts at Cleafy are concerned that the malware may also target devices in other markets, as the app is under active development.

BingoMod’s evasion techniques have helped the app avoid detection by well-known tools like VirusTotal, and infected devices can further infect more devices. An unscrupulous person could also remotely wipe the device if the victim granted the BingoMod app device administrator rights, although Cleafy said this would only clear attached external storage.

As always, the best way to avoid these types of phishing attacks is to never click on links from unverified sources, especially links that claim to be important and require an immediate click. Be sure to prefer installing apps from reputable sources like the Google Play Store, and set up multi-factor authentication where possible to give your online accounts an extra layer of biometric security. A Google spokesperson told foreign media Android Police, Play Protect already protects Android users from known versions of information-stealing malware by blocking the app or showing you a warning, even if the malicious app wasn’t downloaded from the Play Store. Still, we recommend using one of the password managers to keep your credentials safe, and are warning about recent data breaches that may have compromised your account.
Source: KOCPC Chinese