Foreign media reports indicate that a “touch-and-pay” malicious software targeting Andre equipment is spreading, and that the attackers, with the help of the immediate communications function and infected equipment, may directly initiate unauthorized payments or transfers, thereby stealing funds from some user bank accounts.

Target the cell phone payment link.

It was reported that malicious software was primarily intended for Andre users. The assailants induce the user to install the application with a wooden horse, or to acquire the right to the equipment by means of disguise updates, counterfeit services, etc. Once the critical function of the mobile phone is controlled, hackers may initiate operations with the ability to “touch and pay”.

Unlike traditional fishing, such attacks are closer to abuse of payment terminals themselves. Even if they did not voluntarily disclose the bank card number, the victim may face a loss of account funds because the equipment is controlled.

Bank account funds were transferred directly.

It was reported that some of the victims ' bank account funds were transferred directly. Since payments may be made by mobile phone, users often realize anomalies only after the transaction has taken place. For users who rely on the binding of mobile wallets and bank cards, the risk is more focused on equipment rights management and the review of the source of application.

  • Install an unknown source APK or counterfeit application
  • Accessibility to unknown programs, NFC, etc.
  • Enter sensitive information in abnormal bullet windows or disguise pages

Mobile payments are being secured again.

Once again, the incident revealed that, following the widespread use of mobile payments, the target of the attack had shifted from simply stealing account information to using the payment process itself. For banks, payment platforms and mobile phone manufacturers, it is becoming more important to limit unusual access and to identify suspicious payments.

For ordinary users, the reduction of side-loading applications, the careful granting of high-risk privileges and the timely inspection of account transactions remain a direct means of reducing losses.