New Cyber Alert – New Nexus Trojan on Android, Attacking Mobile Banking Accounts
The new Android trojan is being spread through phishing pages disguised as legitimate websites called YouTube Vanced. The botnet, named Nexus, was first made available on a forum in January 2023 for a monthly fee of $3,000 and was described as a “very new” project under “continuous development”. With the rise of the malware-as-a-service model, more hackers are gaining access to this malware by paying for access to additional malware. Once the Nexus trojan infiltrates a victim’s bank accounts, it can drain and steal funds through overlay attacks, where a fake version of a legitimate banking app is superimposed on top of it.
What is the Nexus Trojan Malware?
Capable of operating covertly, the Nexus trojan can avoid detection and security measures. Once installed on a device, it has the ability to intercept and log sensitive information including login credentials, credit card details, and other financial data. The trojan can even copy, log and forward two-factor authentication codes, whether they are sent via text or from the Google Authenticator app. Additionally, it can delete text messages received on the infected device, halt the 2-factor authentication stealer module, and regularly update itself by communicating with a command-and-control server controlled by cyber criminals.
How Can you Protect Yourself?
Implementing Mobile Device Management (MDM), paired with advanced Sign On Authentication tools such as Duo, you can ensure that your mobile devices will be protected from the latest Cyber Threats. Mobile Device Management can ensure that; only Authorised Applications can be downloaded, only specific applications have access to phone features such as clipboard, screen recording, camera & more, protecting your sensitive business information from being accessed by unauthorised applications or malware. Duo authentication also ensures that many of your business applications are protected from unauthorised access by adding in a secondary security step that is not vulnerable to these common authentication code stealer methods.
Latest News Stories
What do Remote Businesses need to Survive? – The Radical Increase of Digital Adoption
Duo, a leading provider of multi-factor authentication and secure access solutions has published a new report. The report highlights the unprecedented IT changes that organisations underwent in 2020 as a result of the massive shift to remote work, and the accelerated...
Popular YouTube Channel ‘Linus Tech Tips’ Suffers Hack
Linus Tech Tips, along with two other Linus Media Group YouTube channels, have been reinstated following a major breach that enabled a malicious actor to carry out activities such as streaming fraudulent crypto videos, modifying channel names, and erasing videos....
Trusted Essential Cyber Insurance for Small Businesses with Managed Service Providers
Did you know about half of all cyber attacks target small to medium sized businesses, with 60% of small business victims closing within six months of an attack. One2Call are an essential ally for small businesses seeking the tools required to gain the right cyber...
Our Customers
Testimonials
James, Proove Restaurant
Very helpful, did exactly what I needed.
The Willows School
What do we like – always polite, they always keep you in the loop, always professional over the phone and In person. great company.
The Willows School
Jordan always goes above and beyond no matter how crazy an idea we have or how quickly something needs doing.