Trojan terror! 450 apps targetted on Google Play Store, says report | Tech News

Trojan terror! 450 apps targetted on Google Play Store, says report

A new Android trojan app has emerged that could take over your bank account and empty it of all your money.

By: HT TECH
| Updated on: Mar 28 2023, 23:25 IST
BEWARE! Here is how NOT to check your PF balance; man loses Rs. 1.23 lakh in scam
Nexus trojan
1/7 In a shocking turn of events, when a man was looking to check his PF balance online, he was caught by fraudsters and lost Rs. 1.23 lakh! (Reuters)
Nexus trojan
2/7 This is how he lost money in this PF balance scam. He was searching for the EPOFO phone number on the Internet, but came across a fake phone number, according to Free Press Journal. He called it and the person there convinced him to download an app that provided the fraudster with remote access to his gadget. He also shared the code for making a payment. Before, the innocent man knew what happened, he had lost the whopping amount of Rs. 1.23 lakh! (Pixabay)
Nexus trojan
3/7 In short, do not check PF balance by searching online and clicking on random links or talking to anyone. Just remember, EPFO will never ask you to make any payment or download any app or even ask you for any payment code or OTP. So, if you want to know how to check PF balance online, we explain it here. (HT_PRINT)
Nexus trojan
4/7 How to check PF balance Via UMANG App - For checking PF Balance via UMANG App, you will first have to download the app and then log in by entering your UAN and OTP (one-time password) to check the PF account balance. (UMANG Twitter)
Nexus trojan
5/7 How to check PF balance Via Text Message – EPFO members whose UANs are registered with EPFO can check their PF balance by sending a text message (SMS) to 7738299899 by typing 'EPFOHO UAN ENG' using your registered mobile number with the UAN (Universal Account Number). It can be noted that the last three digits of the message represents the language in which you want to receive the message. (Pixabay)
Nexus trojan
6/7 How to check PF balance Via Missed Call – Members also have the option of checking the PF balance via call. Registered users can give a missed call to 011-22901406 from their UAN registered mobile number after which they will receive an SMS with details of the PF account balance. (Unsplash)
Nexus trojan
7/7 How to check PF balance Via EPFO website - Visit the EPFO portal www.epfindia.gov.in and click on the ‘For Employees’ option under the ‘Our Services’ dropdown menu. Click on 'Member Passbook' and enter your UAN and password. Once you do so you will be able to see your passbook. It can be noted that people who have worked in more than one organisation will have different member IDs to choose from. (MINT_PRINT)
Nexus trojan
icon View all Images
Nexus trojan is distributed through phishing pages. (Pixabay)

Just days after it was revealed that Xenomorph Android malware has made a comeback, another Android Trojan threat has emerged and although it isn't fully developed yet, it could still lead to disastrous consequences for people around the world. It has been injected into the Google Play Store ecosystem. Google Play Store offers millions of apps for Android users for any and all tasks. Despite Google's attempts, some potentially harmful apps slip through without being detected. The latest Trojan that has created big problems is known as Nexus and it is capable of targeting almost 450 apps on the Google Play Store.

What is Nexus?

According to a report by Cleafy, Nexus first appeared on multiple hacking forums back in January 2023. It is being distributed through phishing pages disguised as legitimate websites of YouTube Vanced, a modified version of YouTube, according to threat intelligence firm Cyble.

The trojan is capable of stealing passwords from banking applications and can intercept both 2FA codes received through text messages, as well as codes generated by the Google Authenticator app.

Although Nexus is still in its developmental stages, it is already capable of causing major harm. Nexus has been introduced on a ‘Malware-as-a-Service' platform where hackers pay other cybercriminals to access their service.

How does it work?

Nexus takes over a bank account by initiating overlay attacks which involves putting an overlay or a fake version on top of a legitimate banking app. When users log in to their accounts, the overlay captures their username and password. Additionally, Nexus has a keylogger that can capture any passwords a user types or autofills on their phone.

Moreover, the latest version of Nexus has the ability to delete text messages received on the infected device, halt its 2FA stealing feature, as well as update itself regularly by pinging a cybercriminal-controlled command-and-control (C&C) server.

How you can stay safe

There are various ways you can stay safe from malicious malware to keep all your banking information away from the hands of cybercriminals and hackers.

1. NEVER download and install apps from unknown sources. Use only Google Play Store to install apps.

2. Never download any apps from third-party app stores.

3. Do not open any links from any of the text messages you receive. Banks never ask customers to install any app from a given link.

4. Install antivirus and antimalware software on your smartphone to keep it safe from any potential malware.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on Whatsapp channel,Twitter, Facebook, Google News, and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 28 Mar, 18:01 IST
NEXT ARTICLE BEGINS