the last week, a fake ad began to appear in Google search results, disguised as…
The fake apps were uploaded to Google Play in June and July 2018 when ESET notified Google they were taken down, but by then they had been installed by hundreds of victims. The apps were uploaded under three different developer names, each impersonating a different Indian bank: however, all three apps can be traced back to a single attacker.
The information-stealing aspect of the operation is also very straightforward. The victim is presented with a form asking for names, credit card numbers, expiration dates and CVV. This is then submitted and the person is taken to another screen where he or she is asked for their banking login credentials. When the second form is submitted the person is told a “customer service executive” will soon be in contact.
More info in ESET report.
News-bpudepi.today is a domain that tries to trick you into subscribing to its browser notifications…
Doguhtam.xyz is a site that tries to trick you into subscribing to its browser notifications…
News-xlixoti.com is a site that tries to force you into subscribing to its browser notifications…
Ducesousightion.com is a domain that tries to trick you into clik to its browser notifications…
News-xlabica.live is a domain that tries to trick you into clik to its browser notifications…
Mergechain.co.in is a site that tries to trick you into subscribing to its browser notifications…