Cloned Banking App Steals User ID Only

Status
Not open for further replies.

Littlebits

Retired Staff
Thread author
May 3, 2011
3,893
- Rogue banking app has been removed
Google Play is not famous for providing legitimate apps only, and every once in a while a rogue one sneaks in, despite the automatic analysis tools available for checking the marketplace.

A malicious app called BankMirage has been removed this week by Google Play curators at the alert of Lookout researchers.

BankMirage had been designed as a clone of a legitimate banking app for the customers of a bank in Israel, called Mizrahi Bank. The circumstances that allowed it to make it into the marketplace are unclear and there is no information on the number of users that downloaded it.

When launched, the rogue app would leverage phishing techniques by loading an in-app HTML page presenting a log-in form. One would assume that all the information entered in the fields available would automatically fall into the hands of the crooks.

Well, one would be wrong because it seems that the authors of the app inserted a comment that instructed only the username to be transmitted.

This may be an unintentional flaw, but at least users who downloaded it did not leak the password to their bank accounts.

Lookout says that after the information was captured, BankMirage would return an error message saying that the log-in procedure failed and suggested re-installation of the app; the link to the legitimate banking app would then be provided.

Source
 
  • Like
Reactions: Petrovic and Ink
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top