超過90款惡意程式溜進Google Play,夾雜Anatsa與Coper等金融木馬
支付動態 · 2024-05-29

資安業者警告近期成功混入Google Play市集的惡意程式中,包含偽裝成PDF閱讀器及二維碼閱讀器的金融木馬,目的是竊取使用者憑證,可能帶來嚴重危害

Zscaler

分析顯示,在使用者安裝了任一款閱讀器之後,程式就會藉由假借更新的名義,自駭客所控制的C&C伺服器下載惡意程式碼或階段性酬載,繼之向使用者請求各種許可,諸如簡訊或輔助(Accessibility)等與金融木馬相關的功能,而為了自金融程式中竊取資料,Anatsa會下載一個金融程式目標清單,掃描受害裝置是否含有清單上的程式,再與C&C交流,C&C即會根據裝置上所找到的程式提供偽造的登入頁面,以竊取使用者的憑證。

Zscaler說,即使這次它們僅發現少數嵌入Anatsa與Coper的金融木馬程式,但它們可能帶來最嚴重的危害,建議各組織應該實施零信任架構,以確保使用者在造訪任何資源之前都必須經過身分驗證與授權。

Popular articles
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
Kazakhstan plans to penalise online casino promotions
Regulation
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
JILI Partners with Cricket Legend AB de Villiers (ABD) to Launch Exclusive Branded Game Series 100% 11
Sports Game
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
British gambling levy rates confirmed for each vertical
Regulation
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
Home
Game
Cooperation
Find
My