New Android Banking Trojan BlankBot Identified, Poses Significant Risks

04 Aug 2024

BlankBot: A New Android Banking Trojan Threat

Threat intelligence experts have recently identified a new Android banking trojan that poses significant risks to users. Dubbed BlankBot, this malware is adept at capturing SMS text messages, banking credentials, and even device lock patterns or PINs. What sets BlankBot apart is its stealthy nature; it remains undetected by most antivirus software, making it a particularly insidious threat.

The malware was first detected by researchers at Intel 471 on July 24, primarily targeting users in Turkey. Although BlankBot is still believed to be in active development, its capabilities are already alarming. The trojan can perform a variety of malicious actions, including customer injections, keylogging, and screen recording, all while communicating with a control server via a WebSocket connection.

BlankBot Targets Users Of Android 13 And Newer

Currently, BlankBot is distributed through various utility applications aimed at Android users. Its ability to evade detection by most antivirus programs is concerningly familiar to those who have encountered other malware threats. To gain full control over an infected device, BlankBot exploits Android accessibility services.

Upon installation, users are prompted to grant necessary accessibility permissions under the guise of ensuring proper functionality. However, what remains hidden is the absence of an application icon or any visible interface. Instead, users are met with a blank screen that claims an app update is in progress, advising them not to interact with the device. In reality, the trojan is securing permissions in the background and establishing a connection to a malicious control server.

If the device runs on Android 13 or newer, BlankBot employs a session-based package installer that circumvents restricted settings, prompting users to allow installations from third-party sources. This tactic enables the malware to maintain persistence on the device, effectively locking users out of critical settings.

Mitigating BlankBot Infection

While BlankBot is still evolving, researchers emphasize that it can be thwarted by adhering to fundamental security practices. The most crucial advice is to download applications exclusively from official app stores and to avoid side-loading apps, regardless of their allure. Additionally, users should exercise caution when granting permissions, particularly accessibility permissions, which can grant an application extensive control over the device.

It’s essential to question the necessity of such permissions and consider whether alternative applications from reputable sources can provide similar functionality without the associated risks.

I have reached out to Google for a statement.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6399110
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1276585
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
496013
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453735
downloads

News and reviews for Mobile Android

Google Explores Search Tool for Play Store Reviews

Google considers a review search tool for Play Store, enhancing navigation and usefulness for app evaluations.

Read more

Free Saving Apps Streamline Budgeting on Android

Discover five Android saving apps boosting financial efficiency through cashback, budgeting, and rewards.

Read more

Boost Finances with Free Savings Apps

Explore free savings apps for cashback, budgeting, and subscription management. Optimize finances with Upside, Ibotta, PocketGuard, Fetch, and Rocket Money.

Read more

Epic Games Store Offers Free Bundle for Idle Champions Players

Epic Games Store gives away Nixie's Champions of Renown for Idle Champions on Android & iOS until 2023-11-13. Enhance your hero roster.

Read more

Nintendo Store App Launches for Android and iOS

Nintendo has launched a Nintendo Store app for Android and iOS, offering Switch hardware and games. This expands Nintendo's mobile presence.

Read more

Optimize Streaming on Android TV with Key Apps

Discover essential streaming apps for Android TV, featuring stable performance and a user-friendly interface. Enhance your viewing experience today.

Read more

Gemini Replaces Google Assistant in Android Auto Rollout

Gemini is now replacing Google Assistant in Android Auto starting 2025-11-05, enhancing language and integration features.

Read more

Google Adds Theme Packs to Pixel Phones

Google introduces Theme Packs on Pixel via an app, enhancing customization with styles like Glinda and Elphaba.

Read more

Proton VPN Embeds NetShield in Android TV App Update

Proton VPN integrates NetShield into its Android TV app, enhancing privacy for paid users with ad-blocking features and DNS protection.

Read more

Herodotus Trojan Exploits Android Devices Through Phishing

Herodotus, an Android Trojan, spreads rapidly via SMS phishing, affecting banking apps' security with advanced evasion tactics.

Read more