June 19, 2019 By David Bisson 2 min read

Security researchers discovered two malicious Android apps that leveraged a clever two-factor authentication (2FA) bypass to steal Turkish users’ cryptocurrency credentials.

ESET discovered two malicious apps capable of using this 2FA bypass on the Google Play store. A developer named BTCTurk Pro Beta uploaded the first app — similarly dubbed BTCTurk Pro Beta — on June 7. The second app, sBtcTurk Pro Beta, arrived on Google Play on June 11 from a developer named BtSoft. Both of these apps registered around 50 downloads before the Slovakian security firm reported them to Google’s security team.

Upon installation, the apps request a permission known as Notification Access. This privilege enables the app to read notifications from other apps, dismiss them and click on buttons within those notifications. Notifications include SMS messages containing 2FA codes.

When granted, the malicious apps direct users to a fake login page for Turkish cryptocurrency exchange BtcTurk. The apps then display an error message while they secretly send those login credentials to a remote server. The individuals behind this campaign use those details as well as the Notification Access permission to authenticate themselves, conceal any 2FA prompts and empty their victims’ cryptocurrency accounts.

The Limitations of SMS-Based 2FA

These malicious apps illustrate the long-running limitations of SMS-based 2FA. In December 2018, for example, ESET came across an Android Trojan designed to steal funds out of mobile users’ PayPal accounts, including those protected by 2FA. Earlier that year, attackers used SMS intercept techniques to bypass 2FA in a security incident that affected some computer systems of Reddit.

Prepare for the Next Mobile 2FA Bypass Threat

To help defend their organizations against mobile malware that comes with a 2FA bypass, security leaders should invest in a unified endpoint management (UEM) solution that uses compliance rules and detection logic to scan for mobile malware. Companies should also protect corporate-owned mobile devices by keeping software up to date, implementing password best practices and writing security policies that limit app installations to official marketplaces.

More from

How I got started: Incident responder

3 min read - As a cybersecurity incident responder, life can go from chill to chaos in seconds. What is it about being an incident responder that makes people want to step up for this crucial cybersecurity role?With our How I Got Started series, we learn from experts in their field and find out how they got started and what advice they have for anyone looking to get into the field.In this Q&A, we spoke with IBM’s own Dave Bales, co-lead X-Force Incident Command…

Zero-day exploits underscore rising risks for internet-facing interfaces

3 min read - Recent reports confirm the active exploitation of a critical zero-day vulnerability targeting Palo Alto Networks’ Next-Generation Firewalls (NGFW) management interfaces. While Palo Alto’s swift advisories and mitigation guidance offer a starting point for remediation, the broader implications of such vulnerabilities demand attention from organizations globally.The surge in attacks on internet-facing management interfaces highlights an evolving threat landscape and necessitates rethinking how organizations secure critical assets.Who is exploiting the NGFW zero-day?As of now, little is known about the actors behind the…

How TikTok is reframing cybersecurity efforts

4 min read - You might think of TikTok as the place to go to find out new recipes and laugh at silly videos. And as a cybersecurity professional, TikTok’s potential data security issues are also likely to come to mind. However, in recent years, TikTok has worked to promote cybersecurity through its channels and programs. To highlight its efforts, TikTok celebrated Cybersecurity Month by promoting its cybersecurity focus and sharing cybersecurity TikTok creators.Global Bug Bounty program with HackerOneDuring Cybersecurity Month, the social media…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today