Blog
January 12, 2022
2
MIN READ
Ghimob malware can spy on 153 Android mobile applications

Share this post

TABLE OF CONTENT

They are warning about a new Android trojan “Ghimob” that can siphon off data from 153 mobile applications. The risk isn’t limited to data breach threats – the attackers can even bypass banking institutions’ security measures to make fraudulent transactions on Android users’ smartphones.

With a link in an email that takes the users to an authentic-looking app, mostly provided by a fraudulent potential creditor, the Ghimob trojan installs and sends a message back to the command-and-control (C2) server containing the victims’ phone data, including the model and the screen lock details. With a very strong persistence, this is how a Ghimob trojan steals sensitive information from 153 android applications.

This advisory by SISA answers a few critical questions:

  • How does a Ghimob trojan work?
  • How advanced is a Ghimob attack as compared to any other mobile banking trojan?
  • What are the indicators of a Ghimob attack?
  • What are some effective mitigation steps?

The editorial team at SISA Information Security hopes that by leveraging this advisory, organizations will be armed with the necessary awareness and knowledge to protect their environments from trojans like Ghimob.

Get your copy now!

Download Blog

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Thank you!

Please click on button to download

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

SHARE THIS POST

Breach Response
Sappers DFIR
Malware