Malaysia

Fake online shop scam targets Malaysian Android users: report

Cybersecurity firm Eset Research says malicious apps aim for customer banking data

Updated 2 years ago · Published on 06 Apr 2022 8:00PM

Fake online shop scam targets Malaysian Android users: report
According to the report, smartphones account for 69% of all retail website visits worldwide, and 57% of online shopping orders in the first quarter of last year. – Pixabay pic, April 6, 2022

by A. Azim Idris

KUALA LUMPUR – Cybercriminals have been deploying malicious Android apps parading as e-stores for legitimate Malaysian businesses since late last year to farm sensitive banking details of customers, according to a report released today by cybersecurity firm Eset Research.

The report said the attacks have come from seven fake websites mirroring the websites of six companies offering cleaning services and one pet store, through which customers are then tricked into downloading the malicious apps onto their smartphones.

“The copycat websites do not provide an option to shop directly through them. Instead, they include buttons that claim to download apps from Google Play,” the report said.

“However, clicking these buttons does not actually lead to the Google Play store, but to servers under the threat actors’ control.”

Customers who download the apps will be asked to enable the “install unknown apps” option, after which they are presented with payment options that include credit card and direct bank transfers.

Choosing the direct transfer option will bring victims to a fake FPX payment page listing eight banks – Maybank, Affin Bank, Public Bank Berhad, CIMB, BSN, RHB, Bank Islam Malaysia, and Hong Leong Bank.

However, the FPX page will return error messages after victims input their user IDs and passwords, which are instead sent to malware operators who forward all SMS messages received by the victim in case they contain two-factor authentication codes sent by their bank, the report said.

Eset researcher Lukáš Štefanko said smartphone users must be vigilant and check that they are browsing legitimate websites, and be circumspect when clicking on ads and paid search engine results.

Android users should also make sure they are redirected to the Google Play Store when clicking on download links, and use mobile security solutions on top of two-factor authentication to secure their devices, Štefanko said.

According to the report, smartphones accounted for 69% of all retail website visits worldwide, and 57% of online shopping orders in the first quarter of last year. It also noted that 53% of smartphone users use vendor-specific apps. – The Vibes, April 6, 2022

Related News

Malaysia / 3d

Banks warn about scammers who impersonate NSRC officers

Malaysia / 1mth

60-year-old woman loses more than RM3.4 million in forex scam

Malaysia / 3mth

Elderly woman loses RM800,000 to digital investment scam

Malaysia / 3mth

Fake lawyers promising to recover money lost to scams, says SUPP

Malaysia / 4mth

Alarm over rising online financial scams exploiting people's vulnerabilities

Malaysia / 6mth

Sarawak cops attempt to rescue 51 locals cheated, stranded in Myanmar

Spotlight

Malaysia

PRS proposes party president to fill vacant Senate president’s post

Malaysia

Ex-inspector escapes gallows, gets 33 years for wife’s murder

Malaysia

Foreigners make up 10% of Malaysia population

Malaysia

Cop pleads not guilty to student’s murder

Malaysia

Banks warn about scammers who impersonate NSRC officers

Malaysia

Jeffrey recalls memories of ISA confinement 33 years later

By Jason Santos

You may be interested

Malaysia

Quickly address healthcare shortage in govt hospitals, Putrajaya told

Malaysia

‘Inspector Sheila’ fails to quash public nuisance charge

Malaysia

Masked man kills 2 cops in attack on Johor police station

Malaysia

Sabah’s 40% revenue claim more than just 'aspirational', says CM

Malaysia

Police identify 20 Jemaah Islamiyah members in Johor

By Alfian Z.M. Tahir

Malaysia

SLS appeal hearing draws strong police presence

Malaysia

Political shifts, persistent poverty of Kota Marudu

By Jason Santos

Malaysia

Ex-Bangi MP proposes 4 names to fill EC chair