According to Zimperium, hackers were launching an attack on 217 Android financial applications, with the aim of stealing the user ' s PIN code, pattern unlocks and passwords. The techniques are mainly centred around a counterfeit interface and malicious processes, and are affected by a wide range of financial instruments.
Attack technique
Hackers induce users to enter sensitive information and then retransmit the data back to the attacker-controlled system. Zimperium noted that such attacks were often carried out through malicious software disguised as normal applications.
Affected applications
The named 217 applications relate to financial-related scenarios. The report does not include a full list, but emphasizes that the targets of the attackers are not limited to a single platform, but are directed towards a wide range of financial applications in the Anjo ecology.
Security risks
User accounts may be exposed to unauthorized access if PIN codes, pattern locks or passwords are stolen. For applications that rely on a mobile end for login and payment, such attacks directly impact account security.
