Ginp Android Banking Trojan demands money for showing people infected with COVID-19 nearby – don’t fall for the bait - March 23, 2020
News
News
This article was published more than 3 years ago and the content may be outdated.

Ginp Android Banking Trojan demands money for showing people infected with COVID-19 nearby – don’t fall for the bait

Monday, March 23, 2020

Company: Kaspersky

The infamous Ginp banking Trojan, which acquired the ability to insert fake text messages into the inbox of a regular SMS app back in March, has now acquired a new functionality—one that takes advantage of the recent pandemic.  

Once downloaded on a victim’s phone, the Ginp Trojan can receive a command from the attacker to open a webpage titled “Coronavirus Finder”, which claims there are people nearby infected with the virus. In order to learn where these individuals are, the victim is asked to pay .75 euros. If the victim agrees, he or she is transferred to a payment page. Once the payment details have been entered, however, the victim is neither charged this sum nor does he or she receive any information about those “infected”. Instead, their credit card information has just been handed over to cybercriminals.

Ginp is a Trojan that has rapidly evolved since it first appeared, consistently acquiring new capabilities. In addition, while in the past the targets have primarily been residents of Spain, the name of this latest version suggests the attackers are planning to target other countries.

 “Cybercriminals have, for months, attempted to take advantage of the coronavirus crisis by launching phishing attacks and creating coronavirus-themed malware. This is the first time, though, we’ve seen a banking Trojan attempting to capitalize on the pandemic. It’s alarming, particularly since Ginp is such an effective Trojan. We encourage Android users to be particularly vigilant at this time—pop-ups, unfamiliar webpages, and spontaneous messages about coronavirus should always be viewed skeptically,” says Alexander Eremin, security expert at Kaspersky.

Kaspersky products successfully detect and block the threat.

Read more about Ginp on Kaspersky Daily.

To reduce the risk of being exposed to Ginp or other banking Trojans, Kaspersky experts recommend:

  • Only download apps from the official Android Stores.
  • Don’t click on suspicious links and never give away sensitive information, such as passwords or credit card information
  • Install a reliable security solution on your phone, like Kaspersky Internet Security for Android, that protects from a wide range of threats including banking Trojans

Additional Resources from Kaspersky

Kaspersky White Papers

Global Sponsor - Prosegur
Global Sponsor - FIS
Global Sponsor - Diebold Nixdorf
Global Sponsor - Euronet Worldwide
Global Sponsor - KAL
Global Sponsor - PAI
Global Sponsor - DPL
Global Sponsor - Auriga
Become a Global Sponsor
Special Offer Image ATM Security Association Image Special Offer Image
Global Sponsors