Android malware alert: Fake IPTV apps will steal your bank details


A new Android malware called “Massiv” is on the rise. ThreatFabric security researchers discovered the large-scale campaign, in which hackers disguised and distributed the malware as a harmless IPTV streaming application. However, once installed, the app was able to read on-screen inputs to steal passwords and banking details.
The malware is classified as very dangerous and uses screen overlays and keylogging to obtain sensitive data. It can even bypass the usual protection mechanisms of banking applications, designed to protect against the capture of content on the screen.
According to researchers, the malware can even be used to remotely control compromised devices. In some of the cases studied, the attackers also stole users’ identities and were even able to open new financial accounts in their names. It is suspected that these accounts are used for money laundering purposes.
IPTV streaming apps as bait
In its report, ThreatFabric addresses the current trend of hiding malware and other malicious software behind IPTV applications. Over the past 8 months, hackers have increasingly used these streaming apps as bait.
Note that IPTV offers are both legal and illegal. Legal versions can be found in official stores such as the Google Play Store, while illegal versions are mainly offered through third-party sites and may violate copyright laws. In the case of Massiv malware, the applications offered are useless: they cannot be used for legal or illegal streaming.
To ensure the app stays active long enough to download malware in the background, attackers use copies of real IPTV websites to distract users. Most of the cases studied come from Europe, with users in Portugal being Massiv’s main target so far.
How to protect yourself
Download only verified apps from reputable providers available in official app stores such as the Google Play Store. Enable Google Play Protect. Never grant unnecessary permissions to newly installed apps. Install a reputable antivirus application for additional protection.
Further reading: This Android security app is actually malware



