December 22, 2016 By Mark Samuels 2 min read

In addition to the huge threat banking Trojans already pose to financial firms, cybercriminals are now attaching file-encrypting ransomware programs to create a new level of danger for mobile users. Two banking Trojans, known as Faketoken and Tordow 2.0, have combined to both pilfer information and lock files on Android devices.

Cybercriminals continue to spread their ransomware techniques around the globe. IT decision-makers should be aware of the revised Trojans and ensure that Android applications on enterprise devices are used with care.

Faketoken and Tordow 2.0: A Dual Threat to Banks

The original purpose of the Faketoken Trojan was to create fake login screens so fraudsters could steal credentials through financial applications, according to CSO Online. The creators have now inserted the capability to encrypt files held on a phone’s SD card.

Researchers at Kaspersky Lab reported that the new version of Faketoken can steal credentials from more than 2,000 Android finance apps. They estimated that Faketoken has already affected more than 16,000 people in 27 countries.

Faketoken continually asks the user for permissions after it has been installed and tries to replace application shortcuts with substitute icons. The Register reported that malicious coders are probably using this method as the foundation for further damage.

The Root of the Problem

Meanwhile, Comodo Threat Research Labs recently discovered that another mobile banking Trojan known as Tordow 2.0 was affecting users in Russia. Tordow 2.0 is the first mobile banking Trojan that requests root privileges on infected Android devices.

Root access gives cybercriminals the ability to affect a series of functions, such as downloading programs, accessing contacts and renaming files. Although the majority of victims have been located in Russia so far, Comodo pointed out that successful cybercriminal techniques are often spread around the world.

Tordow 2.0 is being spread through popular social media and gaming apps that are impaired by malevolent coders. These hijacked apps are often disseminated from third-party sites that are not affiliated with official stores.

Busting Banking Trojans

The good news, according to the Kaspersky researchers, is that file encryption is not currently popular with mobile ransomware developers, perhaps due to the fact that files on mobile device are often copied to the cloud.

However, the revised versions of these Trojans provide more evidence as to why users should be careful when it comes to app permissions. In September, Kaspersky advised Android users to avoid installing apps from unofficial sources and to use antivirus tools to protect their devices.

Additionally, security researcher Graham Cluley suggested that Android users consider forgoing banking apps on their mobile devices altogether. Any malware would then be unable to steal sensitive data, he reasoned.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today