New Android Banking Trojan BlankBot Identified, Poses Significant Risks

Apps & Games / Mobile / Android / New Android Banking Trojan BlankBot Identified, Poses Significant Risks
04 Aug 2024

BlankBot: A New Android Banking Trojan Threat

Threat intelligence experts have recently identified a new Android banking trojan that poses significant risks to users. Dubbed BlankBot, this malware is adept at capturing SMS text messages, banking credentials, and even device lock patterns or PINs. What sets BlankBot apart is its stealthy nature; it remains undetected by most antivirus software, making it a particularly insidious threat.

The malware was first detected by researchers at Intel 471 on July 24, primarily targeting users in Turkey. Although BlankBot is still believed to be in active development, its capabilities are already alarming. The trojan can perform a variety of malicious actions, including customer injections, keylogging, and screen recording, all while communicating with a control server via a WebSocket connection.

BlankBot Targets Users Of Android 13 And Newer

Currently, BlankBot is distributed through various utility applications aimed at Android users. Its ability to evade detection by most antivirus programs is concerningly familiar to those who have encountered other malware threats. To gain full control over an infected device, BlankBot exploits Android accessibility services.

Upon installation, users are prompted to grant necessary accessibility permissions under the guise of ensuring proper functionality. However, what remains hidden is the absence of an application icon or any visible interface. Instead, users are met with a blank screen that claims an app update is in progress, advising them not to interact with the device. In reality, the trojan is securing permissions in the background and establishing a connection to a malicious control server.

If the device runs on Android 13 or newer, BlankBot employs a session-based package installer that circumvents restricted settings, prompting users to allow installations from third-party sources. This tactic enables the malware to maintain persistence on the device, effectively locking users out of critical settings.

Mitigating BlankBot Infection

While BlankBot is still evolving, researchers emphasize that it can be thwarted by adhering to fundamental security practices. The most crucial advice is to download applications exclusively from official app stores and to avoid side-loading apps, regardless of their allure. Additionally, users should exercise caution when granting permissions, particularly accessibility permissions, which can grant an application extensive control over the device.

It’s essential to question the necessity of such permissions and consider whether alternative applications from reputable sources can provide similar functionality without the associated risks.

I have reached out to Google for a statement.

Update: 04 Aug 2024

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
4841642
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
802269
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
414833
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
289477
downloads

News and reviews for Mobile Android

Android 16 Update to Introduce Taskbar Overflow Feature

Android 16 Update to Introduce Taskbar Overflow Feature

The upcoming Android 16 update will add a taskbar overflow feature to enhance app switching, making it easier to manage apps on busy taskbars. The function is expected to be available in QPR1 or QPR2 by year-end.

Cyberlords Leads August 2025 Android App Deals

Cyberlords Leads August 2025 Android App Deals

Cyberlords highlights Android game deals in August 2025. Offers include Cyberlords – Arcology and MAYATCH. Set in 2173, players lead cyber-warriors on infiltration missions.

Exploring Camera App Designs and Usability Trends

Exploring Camera App Designs and Usability Trends

Samsung and Apple explore divergent paths in camera app design, balancing usability and minimalism. While Apple's app embodies simplicity, Samsung focuses on intuitive user interfaces. Could usability hold more value for Android developers?

Top Limited-Time Free Apps Now Available for Download

Top Limited-Time Free Apps Now Available for Download

Explore the latest free apps, now available on the Apple App Store and Google Play for a limited time. Act quickly to download these mobile treasures before they revert to paid versions.

Candy Crush Continues to Captivate Mobile Gamers Worldwide

Candy Crush Continues to Captivate Mobile Gamers Worldwide

Candy Crush Saga remains a beloved puzzle game, engaging players with its strategic challenges and vibrant visuals across multiple platforms.

NotebookLM Enhances Gaming Guide Consolidation for Handhelds

NotebookLM Enhances Gaming Guide Consolidation for Handhelds

Explore how NotebookLM leverages AI capabilities for strategy guide management on gaming handhelds, overcoming limitations of new chatbots like Gemini.

Phishing Risk from Fake Android Apps Threatens Wallets

Phishing Risk from Fake Android Apps Threatens Wallets

Phishing scams via fake Android apps are on the rise, endangering users' cryptocurrency wallets. It's crucial for users to verify app legitimacy and safeguard mnemonic phrases to protect their assets.

Magnifier App Advances with Live-View Text Search Feature

Magnifier App Advances with Live-View Text Search Feature

Google's Magnifier app, an accessibility tool, now includes live-view text search, simplifying real-time text retrieval and enhancing user experience.

Gemini Enhances Google Docs AI Features on Android

Gemini Enhances Google Docs AI Features on Android

Google Docs on Android introduces Gemini, boosting AI features for users. This update aids in document management, offering tools like content summarization and draft generation. Business users benefit first, as Gemini saves time by automating tasks through new functionalities.

Foundation Empowers Developers with Third-Party AI Access

Foundation Empowers Developers with Third-Party AI Access

Apple introduces Foundation Models framework, offering iOS developers seamless AI integration with minimal code, enhancing app capabilities offline.

All article