October 18, 2016 By Douglas Bonderud 3 min read

Just when it seems like malware-makers have reached the end of their ingenuity, something like the Acecard Android Trojan pops up to remind security professionals that cybercriminals aren’t out of ideas — they’re just working on new projects.

According to SC Magazine, this one could pose a serious problem. Designed to run in the background, Acecard monitors when users open specific apps, then asks them to take a selfie while holding their ID. So far, the code has only been spotted in Singapore and Hong Kong, but with such a lucrative potential payout, it’s a safe bet Acecard is eventually coming to America.

Say Cheese!

So how does this app convince users to give up highly personal data and then take pictures of themselves while holding their IDs? As noted by Softpedia, the first step involves sneaking onto Android devices.

A previous version of the Trojan used a Black Jack app from the official Google Play store. The search giant cracked down, but the Trojan is now making the rounds on third-party sites, hiding in apps that claim to be Flash players or adult-content delivery systems. By masquerading as a legitimate service, this malware gains the ability to ask for admin permissions once installed on any Android device.

Of course, asking for permission isn’t the same as getting carte blanche, so how are cybercriminals convincing users to say yes? Constant annoyance appears to be the method of choice, with users being continually bombarded with permission-request screens until they finally give in and accept.

The Android Trojan is then free to scan for specific apps that require user authentication to open — such as Google Play, Facebook or Dropbox — and start asking for details. First up are requests for credit card data, along with the user’s name, birthday and address. But that’s just the beginning.

Victims are also asked to take a picture of the front and back of their ID card or passport, in addition to a selfie that shows them holding up the same ID. From the user’s perspective, this is a rather laborious verification process; for malicious actors, it’s a gold mine.

An Android Trojan’s Mass Appeal?

Once attackers have this kind of personal data in hand, it’s possible to do just about anything — open a bank or credit card account, transfer funds or take control of social media accounts. This brings up an interesting point: With so much at stake, why would users be willing to enter this kind of personal information?

The answer lies in ubiquity. Smartphone use now outpaces traditional desktop internet access in many countries thanks to the falling price of devices and increasing availability of Wi-Fi hot spots. As a result, many users simply aren’t aware of the risks surrounding third-party app sellers and assume any legitimate-seeming request for data must be real.

Consider the Ghost Push Trojan. As noted by ZDNet, this was a big deal two years ago, infecting 600,000 Androids per day and allowing the Android malware to install apps, display advertisements and spy on users. Newer versions of the mobile OS fixed the problem, but despite the roll out, over 50 percent of users still haven’t upgraded and remain at risk. Any device running Android Lollipop is vulnerable.

The takeaway? Malware-makers are counting on the masses — users who own smartphones or tablets but don’t keep up with the latest in security news, leaving them unaware of emerging threats or the benefit offered by OS upgrades. While user education is part of the solution, the sheer number of smartphones in use and the amount of money on the table makes this a high priority for phone manufacturers and Google’s OS. In a world obsessed with selfies, vanity has now become the newest threat vector.

More from

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today