x

Like our Facebook Page

   
Early Times Newspaper Jammu, Leading Newspaper Jammu
 
Breaking News :   Doctors - The Unsung Heroes of Healthcare | WHEN RS 10 FEELS EXPENSIVE ON A CART, BUT NOT IN A CAFE | Urdu For Naib Tehsildar Recruitment Test | Yatri Niwas in Srinagar | LG Sinha inaugurates SASB Yatri Niwas at Pantha Chowk | LG launches campaign for zero-waste pilgrimage | 'Amarnath Yatra arrangements upgraded' | Heroin worth Rs. 420 crore seized in Rajasthan; Pak-based smuggler, Canada handler named | Within minutes after formation of PAC, NC mocks Sajad Lone’s new political front as ‘BJP’s B-Team’ | CM Omar calls for revival of buyer-creator relationship at SKICC Meet | Salal Dam gates opened amid rising Chenab Water levels | DGP chairs joint security review meeting in Anantnag, visits key areas | Major reshuffle in ACB J&K | From warzone to homeland: Kashmiri students hail India’s rescue mission with tricolour cheers | Security Forces bolster security with hi-tech gadgets | Token distribution for registration begins | Security Forces conduct joint mock drill | India woman footballer Soumya undergoes surgery after nasal bone fracture | Lack of variety in India's bowling attack is concerning: Chappell | National-level minor boxer alleges sexual harassment by woman coach | | MCM launches workshop on Skill Development, Entrepreneurship | GDC Kathua honours NCC Cadet Mohit Kanathia with grand welcome ceremony | Missing person traced from Pallanwala within 2 days | JKHCBAJ unveiles Portrait of Maharaja Hari Singh ji, inaugurated | Four JKAS Officers transferred In Transport Dept Reshuffle | J&K police arrest 87 in drug crackdown, seize narcotics worth Rs 2.42 Cr | Gross GST collections double in 5 years to record Rs 22.08 trillion in FY25 | Srinagar police attaches residential property worth Rs 50 lakh | SKUAST-K holds workshop in Gurez to promote revival of heritage crops | Reasi police solves two theft cases in Katra, accused arrested, stolen property | Union Minister Piyush Goyal to lead transformative FTII Traders conclave | Congress holds impressive Jai Hind Yatra in Poonch City, salutes armed forces, martyrs | Warm, affectionate farewell accorded to retirees of Agriculture Department Jammu | DC Shopian inspects work of rural development projects at Keller | Former JKNPP leaders, senior workers join Apni Party | Committee on Petitions holds meeting in Srinagar | 6000 students participate in NMMSS examination | Ladakh PM Vishwakarma artisans participate in MSME Day celebration | Vi Business’s ready for next - India’s largest digital advisory celebrates growth on MSME day | Indian Army pays tribute to Ex-Serviceman | Civil Defence, Jammu started 5 days CD training programme | Warm send off accorded to Sardar Dharminder Singh Bhargav Head Pharmacist from DHS-J | JKEDI concludes second batch of MDPs in 10 districts | Handicrafts, Handloom Deptt condoles demise of father of Mussrat Islam | IGNOU launches certificate programme for Nurse Managers to Strengthen Managerial Competencies in Nursing Services | Back Issues  
 
news details
New mobile banking virus prowling in Indian cyberspace
9/15/2022 10:12:56 PM
agencies
NEW DELHI, Sept 15: A new mobile banking 'Trojan' virus -- SOVA -- which can stealthily encrypt an Android phone for ransom and is hard to uninstall is targeting Indian customers, the country's federal cyber security agency said in its latest advisory.
The virus has upgraded to its fifth version after it was first detected in the Indian cyberspace in July, it said.
"It has been reported to CERT-In that Indian banking customers are being targeted by a new type of mobile banking malware campaign using SOVA Android Trojan. The first version of this malware appeared for sale in underground markets in September 2021 with the ability to harvest user names and passwords via key logging, stealing cookies and adding false overlays to a range of apps," the advisory said.
SOVA, it said, was earlier focusing on countries like the US, Russia and Spain, but in July 2022 it added several other countries, including India, to its list of targets.
The latest version of this malware, according to the advisory, hides itself within fake Android applications that show up with the logo of a few famous legitimate apps like Chrome, Amazon, NFT (non-fungible token linked to crypto currency) platform to deceive users into installing them.
"This malware captures the credentials when users log into their net banking apps and access bank accounts. The new version of SOVA seems to be targeting more than 200 mobile applications, including banking apps and crypto exchanges/wallets," the advisory said.
The Indian Computer Emergency Response Team or CERT-In is the federal technology arm to combat cyber-attacks and guards the Internet space against phishing and hacking assaults and similar online attacks.
The agency said the malware is distributed via smishing (phishing via SMS) attacks, like most Android banking Trojans.
"Once the fake android application is installed on the phone, it sends the list of all applications installed on the device to the C2 (command and control server) controlled by the threat actor in order to obtain the list of targeted applications."
"At this point, the C2 sends back to the malware the list of addresses for each targeted application and stores this information inside an XML file. These targeted applications are then managed through the communications between the malware and the C2," it said.
The lethality of the virus can be gauged from the fact that it can collect keystrokes, steal cookies, intercept multi-factor authentication (MFA) tokens, take screenshots and record video from a webcam and can perform gestures like screen click, swipe etc, using android accessibility service.
It can also add false overlays to a range of apps and "mimic" over 200 banking and payment applications in order to con the Android user.
"It has been discovered that the makers of SOVA recently upgraded it to its fifth version since its inception, and this version has the capability to encrypt all data on an Android phone and hold it to ransom," it said.
Another key feature of the virus, according to the advisory, is the refactoring of its "protections" module, which aims to protect itself from different victim actions.
For example, it said, if the user tries to uninstall the malware from the settings or pressing the icon, SOVA is able to intercept these actions and prevent them by returning to the home screen and showing a toast (small popup) displaying "This app is secured".
  Share This News with Your Friends on Social Network  
  Comment on this Story  
 
 
 
Early Times Android App
STOCK UPDATE
  
BSE Sensex
NSE Nifty
 
CRICKET UPDATE
 
 
 
 
 
 
 
 
   
Home About Us Top Stories Local News National News Sports News Opinion Editorial ET Cetra Advertise with Us ET E-paper
 
 
J&K RELATED WEBSITES
J&K Govt. Official website
Jammu Kashmir Tourism
JKTDC
Mata Vaishnodevi Shrine Board
Shri Amarnath Ji Shrine Board
Shri Shiv Khori Shrine Board
UTILITY
Train Enquiry
IRCTC
Matavaishnodevi
BSNL
Jammu Kashmir Bank
State Bank of India
PUBLIC INTEREST
Passport Department
Income Tax Department
JK CAMPA
JK GAD
IT Education
Web Site Design Services
EDUCATION
Jammu University
Jammu University Results
JKBOSE
Kashmir University
IGNOU Jammu Center
SMVDU