Malicious App Disguised as a Flash Player That Steals Banking Credentials

Mobile banking users should be aware of a malicious Android app that steals banking login credentials. The malicious banking app called "Android/Spy.Agent.SI," is a Trojan horse that was created by cyber-criminals, and disguised as a Flash Player to trick potential victims into downloading and installing it. The sophisticated banking Trojan or malware is able to create a fake login screen that will steal the potential victims’ online banking credentials and send it to cyber-criminals. The malicious app also has the ability to intercept SMS or text messages and can therefore, bypass SMS or Text Message two-factor authentication security feature, which was created to prevent access to online users’ accounts, even if their credentials (usernames and passwords) were stolen.

Malicious App Disguised as a Flash Player That Steals Banking Credentials

It is important that Android users, who are asked to install Adobe Flash Player, only do so via the Google Play Store.installing Android apps from anywhere else can be dangerous.

Cyber-criminals have created the following malicious websites that have the malicious banking Trojan:

  • www.flashplayeerupdate.com
  • www.adobeflashplaayer.com
  • www.adobeuploadplayer.com
  • www.adobeplayerdownload.com
  • www.adobeupdateplayer.com
  • www.adobeupdateplayeer.com
  • www.adobeupdateflash11.com

The websites above should never be visited since they have the malicious Android file called “FlashPlayer.apk.” The malicious file should never be downloaded or installed. And, Android users should only download apps from the Google Play Store to protect them against malicious apps.

How to Remove the Malicious Banking Android App

In order to remove the malicious app, administrator rights must be disabled or deactivated first. Please see the instructions below:

  • Go to “Settings
  • Select “Security
  • Select “Device administrators
  • Select “Flash Player
  • Select “Deactivate,” ignore the bogus message and choose “OK”.

If you are prevented from carrying out the instructions above, please restart your mobile device in Safe mode and repeat the instructions above.

Once the administrator rights have been removed, the malicious app can be removed using the following instructions:

  • Go to “Settings
  • Select “App/Application Manager
  • Select “Flash Player
  • Select “Uninstall
Check the comment section below for additional information, share what you know, or ask a question about this article by leaving a comment below. And, to quickly find answers to your questions, use our search Search engine.

Note: Some of the information in samples on this website may have been impersonated or spoofed.
Was this article helpful?  +
Share this with others:

Comments, Questions, Answers, or Reviews

There are no comments as yet, please leave one below or revisit.

To protect your privacy, please do not post or remove sensitive information in or from your comments, questions, or reviews. NB: We will use your IP address to display your approximate location to other users when you make a post. That location is not enough to find you.

Your comment, answer, or review will be set as anonymous because you are not signed in. An anonymous comment, answer, or review cannot be edited or deleted, therefore, review it carefully before posting. Sign-in.

Write Your Comment, Question, Answer, or Review

Malicious App Disguised as a Flash Player That Steals Banking Credentials