International Edition
Latest News
Technology

Android banking malware exploits accessibility services to steal funds

Malicious actors are increasingly exploiting popular messaging platforms like Zalo and Facebook Messenger to distribute manipulated Android installation files, aiming to seize complete control of mobile devices and drain financial accounts. In Ahmedabad, India, a 63-year-old man lost…

Android banking malware exploits accessibility services to steal funds

Malicious actors are increasingly exploiting popular messaging platforms like Zalo and Facebook Messenger to distribute manipulated Android installation files, aiming to seize complete control of mobile devices and drain financial accounts. In Ahmedabad, India, a 63-year-old man lost 20,06,305.47 Indian rupees after installing a fake application disguised as official documentation for the PM Awas Yojana state housing program, according to local authorities.

Android Banking Malware Exploits Accessibility Services in Global Heists

Following the installation of the rogue APK, unknown perpetrators gained unauthorized remote access to the victim’s smartphone. Between September 10 and September 22, the attackers executed fraudulent transfers via the Immediate Payment Service (IMPS) network. The stolen funds were extracted from accounts held at the Punjab National Bank, Bank of Baroda, and Bank of India across accounts belonging to the victim, his wife, and an acquaintance. The victim’s son reported the incident via India’s national cybercrime hotline 1930, prompting an active investigation by the Cyber Crime Branch.

RatHat Malware Leverages Wireless Debugging

Security researchers tracking mobile threats have identified sophisticated malware families utilizing similar vector strategies to bypass standard device protections. The Android malware known as RatHat distributes itself through fraudulent Google Play web pages and exploits the operating system’s accessibility permissions to activate wireless debugging and Android Debug Bridge (ADB) shell access.

Security firms Zimperium and Malwarebytes identified 162 infected applications and 12 attacker-controlled servers linked to the RatHat campaign. The malware possesses capabilities to harvest login credentials, passwords, two-factor authentication codes, text messages, and direct input PIN entries.

Gigabud Clones Banking Apps Into Android Work Profiles

Concurrently, IT security firm Group-IB analyzed a 2026 campaign centered around the Gigabud malware. This strain employs a manipulated application named Vwork, registered under the package name net.yy.vwork, to specifically target and clone banking applications inside Android work profiles.

By using accessibility features alongside deceptive overlay screens, the software captures online banking credentials and device unlock codes. Group-IB identified localized variants prepared for deployment across Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, and Germany.

Targeted Attacks on Business Communication Channels

Enterprise and corporate communication tools face parallel threats from structured cybercriminal campaigns. Security laboratory Seqrite Labs issued warnings regarding attacks targeting financial teams, executive leadership, auditors, and business users via platforms like WhatsApp.

Android banking malware exploits accessibility services to steal funds

Attackers hijack compromised accounts to transmit manipulated financial or compliance documents. File formats utilized in these campaigns evolved from VBS and ZIP archives to IMG and VHD disk image files. Advanced variants combine DLL sideloading and Bring Your Own Vulnerable Driver (BYOVD) techniques to evade endpoint security software while deploying remote monitoring tools. Active WhatsApp Web sessions also allow the malware to automatically propagate to stored contacts.

Security analysts advise users to acquire applications strictly through official distribution channels, avoid opening installation binaries received via chat messages, and verify unexpected file attachments through secondary communication channels. Devices suspected of hosting invasive spyware may require a complete factory reset to eradicate persistent threats.

RatHat Android Malware Retains ADB Access After Uninstall | Critical Linux KEVs
About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”