MENU

suburb

  • Loading ...
  • Loading ...

Sunshine Coast Child Care

Latest News Sunshine Coast Child Care

Are you looking for a holiday? Get special deals.

 

New Android malware can empty your bank account in seconds

28 Nov 2025 By foxnews

New Android malware can empty your bank account in seconds

Android users have been dealing with a steady rise in financial malware for years. Threats like Hydra, Anatsa and Octo have shown how attackers can take over a phone, read everything on the screen and drain accounts before you even notice anything wrong. Security updates have helped slow some of these strains, but malware authors keep adapting with new tricks. 

The latest variant spotted in circulation is one of the most capable yet. It can silence your phone, take screenshots of banking apps, read clipboard entries, and even automate crypto wallet transactions. This threat is now known as Android BankBot YNRK, and it is far more advanced than typical mobile malware.

Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide - free when you join my CYBERGUY.COM newsletter

HOW ANDROID MALWARE LETS THIEVES ACCESS YOUR ATM CASH

BankBot YNRK hides inside fake Android apps that appear legitimate when installed. In the samples analyzed by researchers at Cyfirma, the attackers used apps that impersonated official digital ID tools. Once installed, the malware begins profiling the device by collecting details such as brand, model and installed apps. It checks whether the device is an emulator to avoid automated security analysis. It also maps known models to screen resolutions, which helps it tailor its behavior to specific phones.

To blend in, the malware can disguise itself as Google News. It does this by changing its app name and icon, then loading the real news.google.com site inside a WebView. While the victim believes the app is genuine, the malware quietly runs its background services.

One of its first actions is to mute audio and notification alerts. This prevents victims from hearing incoming messages, alarms or calls that could signal unusual account activity. It then requests access to Accessibility Services. If granted, this allows the malware to interact with the device interface just like a user. From that point onward, it can press buttons, scroll through screens and read everything displayed on the device.

BankBot YNRK also adds itself as a Device Administrator app. This makes it harder to remove and helps it restart itself after a reboot. To maintain long-term access, it schedules recurring background jobs that relaunch the malware every few seconds as long as the phone is connected to the internet.

Once the malware receives commands from its remote server, it gains near-complete control of the phone. It sends device information and installed app lists to the attackers, then receives a list of financial apps it should target. This list includes major banking apps used in Vietnam, Malaysia, Indonesia and India, along with several global cryptocurrency wallets.

With Accessibility permissions enabled, the malware can read everything shown on the screen. It captures UI metadata such as text, view IDs and button positions. This helps it reconstruct a simplified version of any app's interface. Using this data, it can enter login details, swipe through menus or confirm transfers. It can also set text inside fields, install or remove apps, take photos, send SMS, turn call forwarding on and open banking apps in the background while the screen appears inactive.

In cryptocurrency wallets, the malware acts like an automated bot. It can open apps such as Exodus or MetaMask, read balances and seed phrases, dismiss biometric prompts, and carry out transactions. Because all actions happen through Accessibility, the attacker never needs your passwords or PINs. Anything visible on the screen is enough.

The malware also monitors the clipboard, so if users copy OTPs, account numbers or crypto keys, the data is immediately sent to the attackers. With call forwarding enabled, incoming bank verification calls can be silently redirected. All of these actions happen within seconds of the malware activating.

Banking trojans are getting harder to spot, but a few simple habits can reduce the chances of your phone getting compromised. Here are seven practical steps that help you stay protected. 

FBI WARNS OVER 1 MILLION ANDROID DEVICES HIJACKED BY MALWARE

Strong antivirus software helps catch trouble early by spotting suspicious behavior before it harms your Android device or exposes your data. It checks apps as you install them, alerts you to risky permissions and blocks known malware threats. Many top antivirus options also scan links and messages for danger, which adds an important layer of protection when scams move fast.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Data brokers quietly collect and sell your personal details, which helps scammers target you with more convincing attacks. A reputable data-removal service can find and delete your information from dozens of sites so that criminals have less to work with. This reduces spam, phishing attempts and the chances of ending up on a malware attack list.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren't cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It's what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

Avoid downloading APKs from random websites, forwarded messages or social media posts. Most banking malware spreads through sideloaded apps that look official but contain hidden code. The Play Store is not perfect, but it offers scanning, app verification and regular take-downs that greatly reduce the risk of installing infected apps.

System updates often patch security issues that attackers exploit to bypass protections. Updating your apps is just as important, since outdated versions may contain weaknesses. Turn on automatic updates so that your device stays protected without you having to check manually.

A password manager helps you create long, unique passwords for every account. It also saves you from typing passwords directly into apps, which reduces the chance of malware capturing them from your clipboard or keystrokes. If one password gets exposed, the rest of your accounts remain safe.

Next, see if your email has been exposed in past breaches. Our No. 1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials. 

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com

2FA adds a confirmation step through an OTP, authenticator app or hardware key. Even if attackers steal your login details, they still need this second step to get in. It cannot stop malware that takes over your device, but it significantly limits how far an attacker can go with stolen credentials.

GOOGLE ISSUES WARNING ON FAKE VPN APPS

Malware often abuses permissions such as Accessibility or Device Admin because they allow deep control over your phone. Check your settings to see which apps have these permissions and remove anything that looks unfamiliar. Also, look through your installed apps and uninstall any tool or service you do not remember adding. Regular reviews help you spot threats early before they can steal data.

BankBot YNRK is one of the most capable Android banking threats discovered recently. It combines device profiling, strong persistence, UI automation and data theft to gain full control over a victim's financial apps. Because much of its activity relies on Accessibility permissions, a single tap from the user can give attackers complete access. Staying safe means avoiding unofficial APKs, reviewing installed apps regularly and being cautious of any sudden request to enable special permissions.

Do you think Android phone makers like Samsung or Google are doing enough to protect you from malware? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide - free when you join my CYBERGUY.COM newsletter

Copyright 2025 CyberGuy.com.  All rights reserved.

More News

Booking.com
10 things to stop paying for to save money now
10 things to stop paying for to save money now
Sharks in Bahamas found to have cocaine and other drugs in their systems, study says
Sharks in Bahamas found to have cocaine and other drugs in their systems, study says
First of its kind wagon evidence uncovered in massive Iron Age treasure trove
First of its kind wagon evidence uncovered in massive Iron Age treasure trove
Traveler hands out vodka shots in massive TSA line amid US airport lines and delays
Traveler hands out vodka shots in massive TSA line amid US airport lines and delays
Free museums may now slap entry fees on millions of tourists under hotly debated proposal
Free museums may now slap entry fees on millions of tourists under hotly debated proposal
Colorado tried to silence me for helping gender-confused kids. The Supreme Court just ruled 8-1 in my favor
Colorado tried to silence me for helping gender-confused kids. The Supreme Court just ruled 8-1 in my favor
Cowboys coach reacts to Dak Prescott's broken engagement, says NFL star is in a 'good spot' after split
Cowboys coach reacts to Dak Prescott's broken engagement, says NFL star is in a 'good spot' after split
'The View' co-hosts claim Usha Vance is 'addicted to power' in on-air attack against second lady
'The View' co-hosts claim Usha Vance is 'addicted to power' in on-air attack against second lady
Fake Google Meet update lets hackers control your Windows PCs
Fake Google Meet update lets hackers control your Windows PCs
NBA player Jaden Ivey goes on social media rant after being waived amid comments criticizing pride month
NBA player Jaden Ivey goes on social media rant after being waived amid comments criticizing pride month
Iran moderates pushing Trump deal risk being 'eliminated' as regime fractures deepen
Iran moderates pushing Trump deal risk being 'eliminated' as regime fractures deepen
Roseanne Barr reveals 'damaged' heart, fears she will 'die on the surgery table'
Roseanne Barr reveals 'damaged' heart, fears she will 'die on the surgery table'
Israeli comedian drops out of Passover event after learning of Mamdani's attendance
Israeli comedian drops out of Passover event after learning of Mamdani's attendance
Wild bodycam video shows cops storm chaotic teen 'takeover' as businesses trashed: 'They come to fight'
Wild bodycam video shows cops storm chaotic teen 'takeover' as businesses trashed: 'They come to fight'
Kid Rock Nashville home flyover prompts US Army to suspend aircrew
Kid Rock Nashville home flyover prompts US Army to suspend aircrew
Tiger Woods pleads not guilty, demands trial with jury after DUI arrest following rollover crash
Tiger Woods pleads not guilty, demands trial with jury after DUI arrest following rollover crash
Iran's 'basement' Chinese drone networks spark fears of sleeper cell attacks on US soil
Iran's 'basement' Chinese drone networks spark fears of sleeper cell attacks on US soil
Jason Kelce calls out Lions for 'bulls---' contract demand to retired Pro Bowl center
Jason Kelce calls out Lions for 'bulls---' contract demand to retired Pro Bowl center
Molly Sims, 52, stuns in string bikini during Cabo vacation ahead of eighth Sports Illustrated Swimsuit Issue
Molly Sims, 52, stuns in string bikini during Cabo vacation ahead of eighth Sports Illustrated Swimsuit Issue
'Forrest Gump' star Gary Sinise warns many Americans are 'disconnected' from military service
'Forrest Gump' star Gary Sinise warns many Americans are 'disconnected' from military service
Latest News

copyright © 2026 Sunshine Coast Child Care.   All rights reserved.

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z