New Trojan Wave Targets Crypto Wallets and Banking Apps
Zimperium's zLabs team has identified a surge in sophisticated trojans—RecruitRat, SaferRat, Astrinox, and Massiv—targeting Android users managing cryptocurrencies. These malware families operate through distinct command-and-control networks, hijacking login credentials, intercepting financial transactions, and exfiltrating sensitive data in real time.
The trojans deploy fake overlays mimicking legitimate crypto and banking apps, creating what researchers describe as "a highly convincing, deceptive facade." By exploiting Accessibility Services, the malware activates counterfeit login screens precisely when victims launch financial applications, capturing passwords, one-time passcodes, and even live screen feeds.
SaferRat lures victims through fake premium streaming service offers, while RecruitRat disguises itself within job application processes. The malware demonstrates alarming capabilities—disabling uninstall attempts, hiding app icons, and persistently monitoring device activity.
Log in to Reply
Log in to comment your thoughtsComments
Related Articles
|Square
Get the BTCC app to start your crypto journey
Get started today Scan to join our 100M+ users