Indian customers on mobile banking platforms are being targeted by a new type of mobile banking malware campaign using SOVA Android Trojan. This malware captures the credentials when users log into their net banking apps and access bank accounts.
This Malware can collect keystrokes, steal cookies, take screenshots, record videos, and multiple other such attacks.
Best Practices and Recommendations to avoid such attacks are given here-below:
Download apps only from official app stores
Even when downloading the app from official app stores, always review the app details and grant only those permissions which are relevant to the app's purpose
Install Android updates and patches as and when available from Android device vendors and maintain updated anti-virus and antispyware software
Look for suspicious numbers that don't look like real mobile phone numbers. Scammers often mask their identity by using email-to-text services to avoid revealing their actual phone number
Do extensive research before clicking on a link provided in the message and before providing any sensitive information such as personal particulars or account login details. Do not browse un-trusted websites or follow/click on un-trusted links
Exercise caution towards shortened URLs. Users are advised to hover their cursors over the shortened URLs (if possible) to see the full website domain
Customers should report any unusual activity in their account immediately to the respective bank with the relevant details for taking further appropriate actions.