Mazda CX5
Як зробити цифрову копію себе. Ось відео —>

"Hello, is that you in the photo?": how one click on an .apk file can reset your cards and suspend your credit

In the world of Android users, freedom of action has always been the main feature that was flaunted to the owners of closed iPhones. If you want, you can change the interface beyond recognition, if you want, you can download useful utilities directly from the Internet. But it is this freedom in the form of nondescript .apk files (installation packages for Android) that has today turned into an ideal weapon for cybercriminals.

Leave a comment
"Hello, is that you in the photo?": how one click on an .apk file can reset your cards and suspend your credit

In the world of Android users, freedom of action has always been the main feature that was flaunted to the owners of closed iPhones. If you want, you can change the interface beyond recognition, if you want, you can download useful utilities directly from the Internet. But it is this freedom in the form of nondescript .apk files (installation packages for Android) that has today turned into an ideal weapon for cybercriminals.

While Apple fans live in their own closed «pen», where strict moderators try to control every step (there are also fraudulent traps for iPhone owners), Android users walk through a minefield every day. Together with experts from the Ukrainian Interbank Association of Payment Systems Members (EMA), we are figuring out how one careless click on a file with this insidious extension can completely wipe out your bank accounts and even drive you into a debt pit.

Who is SpyNote and how does he get superpowers?

Currently, Ukrainians are being massively attacked by viruses in messengers and on fake websites with a very unpleasant surprise inside — the banking Trojan SpyNote. Cybersecurity experts are tracking the hackers who launch it under the code name UAC-0236.

This isn’t some petty scumbag that just plays annoying ads. It’s a powerful tool that gives hackers complete control over your smartphone remotely.

Its main feature is a cunning double scheme: First, the first dummy program arrives on the phone. It almost does not ask for permissions, does nothing bad, and therefore mobile antiviruses simply do not notice it. But its only real task is to quietly drag the second program into the system, unpack it and install it. And now it is the same combat virus that takes control of your phone.

This Trojan’s weapon is the misuse of Accessibility Service. This feature was designed by Google to help people with disabilities (for example, to voice the screen), but SpyNote uses it as a universal key.

Once the user fraudulently enables this service, the virus gains full control and independently clicks the «Allow» button on all its subsequent requests, instantly collecting the remaining system permissions.

The attack then unfolds in several stages:

Password theft and overlays: When you launch an official bank application, the malware instantly draws a fake window on top of it, copied to the pixel. You enter your username and password there, thinking that you are logging into the bank, and the data is already flying to the hackers. Everything else that is not caught by phishing, the virus picks up with a built-in keylogger (records every keystroke) and constant screenshots.

Covert surveillance: The Trojan does not change passwords to avoid attracting attention, but simply intercepts patterns and PINs through a covert screen broadcast. This allows attackers to even remotely unlock the device if necessary.

Autonomous withdrawal of money: Armed with this data, SpyNote opens banking applications, fills in details, and independently confirms transactions by intercepting one-time codes (OTPs) from SMS or push notifications.

Isolation of the victim: Finally, the virus blocks messengers and phone communication. This is done to cut off the person from contact with the bank and prevent them from raising the alarm in time.

That’s why victims often complain that their banking app simply «hangs» or «doesn’t work» — in fact, the phone is isolated from the owner at this moment and obediently executes commands from the attackers' server.

Traps for every taste: current hacking legends

Today, scammers no longer write primitive letters about «inheritance from a Nigerian prince» (although sometimes they still come). They hit the most painful points of Ukrainians: finding a job during the crisis, financial assistance, patriotism and ordinary human curiosity. And the tool for spreading danger in most cases is aggressive Facebook advertising.

Hunting for «juns» and students: testing applications

This scenario hits young IT specialists without experience or students who are looking for at least some income. An attractive vacancy appears on classifieds sites or Telegram channels: «Android mobile application tester. Work from home, pay from 1,500 to 3,000 hryvnias per hour.»

When an interested victim responds, they are transferred to a messenger. Everything looks solid there: a polite HR manager confirms the terms and asks them to fill out a form with personal data, including a card number — supposedly for future salary payments.

And then comes the time for the first «test task». The candidate is sent the same APK file. The scammers act in advance and immediately warn: «Since the application is new and has not yet been uploaded to the store, your mobile antivirus or Google Play Protect may be scolding. Don’t worry, this is normal for the development process, just turn off the protection and install.» The young man, dreaming of his first job, follows the instructions, gives the application all the privileges — and instead of earning money, he gets a complete breakdown of the device.

The Evolution of OLX Phishing: The Story of Dopomoga24

This scheme starts off classic: you sell something on an ad platform, a «buyer» contacts you and transfers the conversation to Telegram, where they drop a fake link to a supposedly secure payment. A small amount of money is debited from your card. You start to panic.

And here the second act of the play is played out. A person calls you, introducing himself as a bank security officer or even a cyber police officer. He says that a fraudulent attack has been detected, and in order to «save the remaining funds from theft», you need to immediately install a special protective utility. A file called Dopomoga24.apk arrives in the messenger.

Experts have found that this application is a modification of the dangerous BTMOB RAT Trojan. It has a cunning two-stage architecture. The first file you install is completely clean — most antiviruses do not react to it. However, after launching, it silently downloads the second, main component from the network.

This second part already requires total control: access to the microphone, camera, messages and geolocation. Moreover, using the window overlay function, scammers manage to bypass even the procedures of remote identification and liveness detection in government applications (by the way, be sure to read — we published a separate article on this topic). They literally use your face to confirm the taking of microloans from financial companies and open accounts in other banks, where they instantly withdraw all the money.

Quest from monobank that failed

The attempt to play on the brand of a popular bank turned out to be quite high-profile. The scammers created a legend: «Want to work at mono? Download our app and complete an interactive quest for employment.»

In this case, there is good news for the bank’s customers: it was not possible to steal money directly from the monobank application by intercepting control from the attackers. None of the cases were successful due to the strict internal security and fraud monitoring systems that analyze the device’s behavior and block suspicious actions. However, having gained control over the smartphone’s operating system through a malicious APK, criminals can go to other banks, where protection may be weaker.

Adult Moderators and «Martyr Radars»

Fraudsters are actively using the topic of hype and security. One of the targets were those looking for easy money, who were offered a moderator position on OnlyFans. The legend is simple: you need to install a «special working client» to check models’ profiles and pay a test subscription of one hryvnia. As a result, the card details are leaked and the phone is infected.

Another disgusting speculation is the «Martyrs Radar» app. Against the backdrop of constant air alerts, people are being offered to install an unofficial program that supposedly sees approaching drones better than air defense systems. In fact, this app is based on the same code as other social baits, disguises itself as a Google Play update, and, in addition to stealing passwords, additionally uses your phone’s processor to mine cryptocurrency, causing the gadget to literally melt from overheating.

Well, classic spam on Telegram has not disappeared. When a message comes from your friend’s account: «Hello! Is that you anneal in the photo?» or «Terrible accident… Crashed to death, look who…» with the attached file Foto_vypusknogo.apk. Human curiosity and fear work without fail, forcing people to click on the file themselves.

The main rules of digital hygiene: how not to become a victim

Protecting your Android is actually not that difficult if you turn off your emotions and turn on your cold mind. Experts from the EMA Association recommend following a few concrete rules.

First, set a strict taboo on downloading any APK files outside the official Google Play store. Right now, go to your smartphone’s settings and make sure that the «Install from Unknown Sources» feature is completely blocked for all browsers and messengers.

Second, never trust files sent in private messages, even from close friends or relatives. If you are sent an app or a «photo» with an .apk extension, consider it a red flag. Call the person on their regular mobile number and ask what it is — most likely their account has simply been hacked.

Third, be as greedy as possible for permissions. If any newly installed application (especially if it is a calculator, flashlight, fake game, banking app, radar, etc.) persistently asks for access to Accessibility Service or Device Admin rights, immediately delete it. These rights give the program complete control over your screen and keyboard, which is equivalent to voluntarily handing over your gadget to a robber.

Finally, keep your smartphone’s operating system updated to the latest version. Of course, you should have no illusions: fresh Android patches will not magically close all the holes, but will only make it as difficult as possible for hackers to deliver and unpack the Trojan. However, each such barrier created for SpyNote is an additional chance for you to notice the trick. Android freedom is cool, but it requires adult responsibility for every click, because the main line of defense still remains you.

Also Read
У Google розповіли про нову шпигунську програму, що загрожує iOS та Android
У Google розповіли про нову шпигунську програму, що загрожує iOS та Android
У Google розповіли про нову шпигунську програму, що загрожує iOS та Android
Розробник з рф поїхав з країни і тепер готовий безкоштовно навчати українців. Вже є перші зацікавлені
Розробник з рф поїхав з країни і тепер готовий безкоштовно навчати українців. Вже є перші зацікавлені
Розробник з рф поїхав з країни і тепер готовий безкоштовно навчати українців. Вже є перші зацікавлені
«Дія» стала найпопулярнішим додатком для iOS в Україні
«Дія» стала найпопулярнішим додатком для iOS в Україні
«Дія» стала найпопулярнішим додатком для iOS в Україні
Google припинила підтримку старих версій Android. Мільйони користувачів можуть залишитися без пошти, карт і YouTube
Google припинила підтримку старих версій Android. Мільйони користувачів можуть залишитися без пошти, карт і YouTube
Google припинила підтримку старих версій Android. Мільйони користувачів можуть залишитися без пошти, карт і YouTube
2 comments

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.