Android.Bankosy: All ears on voice call-based 2FA
released on 2016-01-25 @ 04:47:51 PM
Android.Bankosy is a Trojan horse for Android devices that steals information from the compromised device.
So how does Android.Bankosy take advantage of voice-based 2FA? Once the malware is installed on the victim’s device, it opens a back door, collects a list of system-specific information, and sends it to the command and control (C&C) server to register the device and then get a unique identifier for the infected device. If the registration is successful, it uses the received unique identifier to further communicate with the C&C server and receive commands.