Connect with us

Technology

New Android malware can empty your bank account in seconds

Published

on

New Android malware can empty your bank account in seconds

NEWYou can now listen to Fox News articles!

Android users have been dealing with a steady rise in financial malware for years. Threats like Hydra, Anatsa and Octo have shown how attackers can take over a phone, read everything on the screen and drain accounts before you even notice anything wrong. Security updates have helped slow some of these strains, but malware authors keep adapting with new tricks. 

The latest variant spotted in circulation is one of the most capable yet. It can silence your phone, take screenshots of banking apps, read clipboard entries, and even automate crypto wallet transactions. This threat is now known as Android BankBot YNRK, and it is far more advanced than typical mobile malware.

Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter

How the malware infiltrates devices

HOW ANDROID MALWARE LETS THIEVES ACCESS YOUR ATM CASH

Advertisement

Android banking malware is getting harder to spot as attackers use new tricks to take over phones and drain accounts. (Thomas Trutschel/Photothek via Getty Images)

BankBot YNRK hides inside fake Android apps that appear legitimate when installed. In the samples analyzed by researchers at Cyfirma, the attackers used apps that impersonated official digital ID tools. Once installed, the malware begins profiling the device by collecting details such as brand, model and installed apps. It checks whether the device is an emulator to avoid automated security analysis. It also maps known models to screen resolutions, which helps it tailor its behavior to specific phones.

To blend in, the malware can disguise itself as Google News. It does this by changing its app name and icon, then loading the real news.google.com site inside a WebView. While the victim believes the app is genuine, the malware quietly runs its background services.

One of its first actions is to mute audio and notification alerts. This prevents victims from hearing incoming messages, alarms or calls that could signal unusual account activity. It then requests access to Accessibility Services. If granted, this allows the malware to interact with the device interface just like a user. From that point onward, it can press buttons, scroll through screens and read everything displayed on the device.

BankBot YNRK also adds itself as a Device Administrator app. This makes it harder to remove and helps it restart itself after a reboot. To maintain long-term access, it schedules recurring background jobs that relaunch the malware every few seconds as long as the phone is connected to the internet.

Advertisement

What does the malware steal

Once the malware receives commands from its remote server, it gains near-complete control of the phone. It sends device information and installed app lists to the attackers, then receives a list of financial apps it should target. This list includes major banking apps used in Vietnam, Malaysia, Indonesia and India, along with several global cryptocurrency wallets.

With Accessibility permissions enabled, the malware can read everything shown on the screen. It captures UI metadata such as text, view IDs and button positions. This helps it reconstruct a simplified version of any app’s interface. Using this data, it can enter login details, swipe through menus or confirm transfers. It can also set text inside fields, install or remove apps, take photos, send SMS, turn call forwarding on and open banking apps in the background while the screen appears inactive.

In cryptocurrency wallets, the malware acts like an automated bot. It can open apps such as Exodus or MetaMask, read balances and seed phrases, dismiss biometric prompts, and carry out transactions. Because all actions happen through Accessibility, the attacker never needs your passwords or PINs. Anything visible on the screen is enough.

The malware also monitors the clipboard, so if users copy OTPs, account numbers or crypto keys, the data is immediately sent to the attackers. With call forwarding enabled, incoming bank verification calls can be silently redirected. All of these actions happen within seconds of the malware activating.

BankBot YNRK hides inside fake apps that look legitimate, then disguises itself as Google News while it runs in the background. (AP Photo/Don Ryan, File)

Advertisement

7 steps you can take to stay safe from banking malware

Banking trojans are getting harder to spot, but a few simple habits can reduce the chances of your phone getting compromised. Here are seven practical steps that help you stay protected. 

FBI WARNS OVER 1 MILLION ANDROID DEVICES HIJACKED BY MALWARE

1) Install strong antivirus software

Strong antivirus software helps catch trouble early by spotting suspicious behavior before it harms your Android device or exposes your data. It checks apps as you install them, alerts you to risky permissions and blocks known malware threats. Many top antivirus options also scan links and messages for danger, which adds an important layer of protection when scams move fast.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Advertisement

2) Use a data-removal service to shrink your digital footprint

Data brokers quietly collect and sell your personal details, which helps scammers target you with more convincing attacks. A reputable data-removal service can find and delete your information from dozens of sites so that criminals have less to work with. This reduces spam, phishing attempts and the chances of ending up on a malware attack list.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

3) Install apps only from trusted sources

Avoid downloading APKs from random websites, forwarded messages or social media posts. Most banking malware spreads through sideloaded apps that look official but contain hidden code. The Play Store is not perfect, but it offers scanning, app verification and regular take-downs that greatly reduce the risk of installing infected apps.

Advertisement

4) Keep your device and apps updated

System updates often patch security issues that attackers exploit to bypass protections. Updating your apps is just as important, since outdated versions may contain weaknesses. Turn on automatic updates so that your device stays protected without you having to check manually.

5) Use a strong password manager

A password manager helps you create long, unique passwords for every account. It also saves you from typing passwords directly into apps, which reduces the chance of malware capturing them from your clipboard or keystrokes. If one password gets exposed, the rest of your accounts remain safe.

Next, see if your email has been exposed in past breaches. Our No. 1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials. 

Once active, the malware can read your screen, steal financial data, automate crypto transfers and intercept OTPs within seconds. (Kurt “CyberGuy” Knutsson)

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com

Advertisement

6) Enable two-factor authentication wherever possible

2FA adds a confirmation step through an OTP, authenticator app or hardware key. Even if attackers steal your login details, they still need this second step to get in. It cannot stop malware that takes over your device, but it significantly limits how far an attacker can go with stolen credentials.

GOOGLE ISSUES WARNING ON FAKE VPN APPS

7) Review app permissions and installed apps regularly

Malware often abuses permissions such as Accessibility or Device Admin because they allow deep control over your phone. Check your settings to see which apps have these permissions and remove anything that looks unfamiliar. Also, look through your installed apps and uninstall any tool or service you do not remember adding. Regular reviews help you spot threats early before they can steal data.

Kurt’s key takeaway

BankBot YNRK is one of the most capable Android banking threats discovered recently. It combines device profiling, strong persistence, UI automation and data theft to gain full control over a victim’s financial apps. Because much of its activity relies on Accessibility permissions, a single tap from the user can give attackers complete access. Staying safe means avoiding unofficial APKs, reviewing installed apps regularly and being cautious of any sudden request to enable special permissions.

Do you think Android phone makers like Samsung or Google are doing enough to protect you from malware? Let us know by writing to us at Cyberguy.com

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter

Copyright 2025 CyberGuy.com.  All rights reserved.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Mark Zuckerberg is taking the stand as social media goes on trial

Published

on

Mark Zuckerberg is taking the stand as social media goes on trial

Lori Schott didn’t care what it took to haul her way from her small town in Eastern Colorado to show up to a Los Angeles courtroom where Meta CEO Mark Zuckerberg is set to testify Wednesday. “I don’t care if I had to hire a pack mule to get me here, I was going to be here,” she told The Verge outside the courthouse Tuesday.

Schott’s daughter Annalee died by suicide at age 18 in 2020, after struggling with body image issues that her mother says were heightened by social media. After her death, Schott found journal entries where Annalee disparaged her own looks and compared herself to other girls’ profiles. “I was so worried about what my child was putting out online, I didn’t realize what she was receiving,” Schott said.

The way that Meta and Google-owned YouTube designed their products — allegedly luring users into a nonstop loop of taps and scrolling — is at the heart of this month’s bellwether social media trial, which sets the stage for thousands of similar lawsuits. The companies have generally denied the claims. Schott and several other self-described survivor parents have made it their mission to be in the courtroom during the several-week trial in downtown LA.

“I was so worried about what my child was putting out online, I didn’t realize what she was receiving.”

Last week, the parents heard from Instagram CEO Adam Mosseri, who used his time to carve a distinction between clinical addiction to social media and what he called “problematic use.” On the stand, Mosseri testified that using Instagram “too much” is a relative thing that can vary person-to-person, and he wouldn’t use the term addiction for using social media up to 16 hours a day. Mosseri explained why Meta had modified a prior ban on image filters that altered users’ appearance, after previously discussing their potential negative mental health effects. While the plaintiff has argued Meta is motivated by profits and engagement at the expense of users’ safety, Mosseri said that the two are aligned. “In general, we should be focused on the protection of minors, but I believe protecting minors over the long run is good for business and for profit,” he said, according to CNBC.

Advertisement

Several parents camped out overnight in the rain to make sure that they would get spots behind Mosseri while he took the stand. One of them was Julianna Arnold, whose daughter Coco died of fentanyl poisoning at 17 after allegedly meeting a dealer on Instagram she believed had sold her Percocet. The parents wore rain ponchos, played cards, drank coffee, and told stories throughout the night. “Everyone was like, you’re crazy,” she said. “But it didn’t feel like we were crazy, because we were so determined to have survivor parents in the courtroom.”

For Schott, who also stayed overnight to see Mosseri’s testimony, the reality of being in the room quickly became overwhelming. “I really hoped in my heart that it wasn’t as bad as it was,” said Schott, who left the testimony early after hearing the Instagram CEO discuss documents about engagement, profits, and internal research about girls’ mental health. “It is that bad.”

“I want him to see my face, because my face is Anna’s face.”

On Wednesday, Zuckerberg will likely expand on Mosseri’s testimony and explain the company’s choices. While Mosseri is in charge of the product at the center of the trial, Zuckerberg’s role as founder and CEO means that the plaintiff’s lawyers will likely ask him to account for choices they allege harmed young users. Zuckerberg will likely be asked about how and why his company made various design decisions, and research it conducted on user safety. But at least as important as what Zuckerberg will say, for many, is that he’ll get to see their faces. “I’d love to look him in the eye,” Schott says. “I want him to see my face, because my face is Anna’s face.”

Zuckerberg’s testimony will likely be referenced at future trials and legislative hearings. Thousands of social media cases behind this one similarly argue that products like Instagram caused various personal injuries, and that companies should be made to pay damages and change their products to make them safer.

Advertisement

Arnold isn’t sure whether she’ll get one of the limited, lottery-assigned seats inside the courthouse. Either way, “I want to see a row of survivor parents in the front row. That he has to testify to our faces, to parents of kids that died because of his lack of care and lack of accountability — that’s why it’s really important that we’re here.”

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

Continue Reading

Technology

Don’t ignore Apple’s urgent security update

Published

on

Don’t ignore Apple’s urgent security update

NEWYou can now listen to Fox News articles!

If you use an iPhone, iPad, Mac, Apple Watch or Apple TV, listen up. Apple has released a major security update to fix a zero-day vulnerability, which is a security hole that hackers discover and exploit before the company has a chance to fix it. 

Attackers were already using it in targeted attacks. In other words, this was not just a possibility. It was happening.

The flaw, tracked as CVE-2026-20700, affects multiple Apple operating systems. If you have delayed updates lately, this is one you should not ignore.

If you own an Android or Windows PC, this is also a good reminder to check for updates. 

Advertisement

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

APPLE PATCHES TWO ZERO-DAY FLAWS USED IN TARGETED ATTACKS

Apple’s latest security updates affect iPhone, iPad, Mac, Apple Watch and Apple TV, so now is the time to check every device you own. (iStock)

What is CVE-2026-20700 and why it matters

CVE-2026-20700 is a memory corruption vulnerability affecting:

  • iOS 26.3
  • iPadOS 26.3
  • macOS Tahoe 26.3
  • watchOS 26.3
  • tvOS 26.3
  • visionOS 26.3

In simple terms, this bug could allow an attacker to run arbitrary code on your device. That opens the door to spyware, hidden backdoors or silent takeovers without obvious warning signs. Apple says this vulnerability was used as part of an infection chain combined with two previously patched flaws against devices running older versions of iOS. Those earlier bugs were fixed in December 2025. Devices that skipped those updates remained exposed. This is how many real attacks unfold. Hackers chain vulnerabilities together and quietly move in.

Which devices need updating?

Here is a breakdown of the available updates:

Advertisement
  • iOS 26.3 and iPadOS 26.3 for iPhone 11 and later, plus newer iPads
  • iOS 18.7.5 and iPadOS 18.7.5 for iPhone XS, XS Max, XR and iPad 7th generation
  • macOS Tahoe 26.3, Sequoia 15.7.4, Sonoma 14.8.4
  • tvOS 26.3 for Apple TV HD and Apple TV 4K
  • watchOS 26.3 for Apple Watch Series 6 and later
  • visionOS 26.3 for Apple Vision Pro
  • Safari 26.3 for supported macOS versions

If your device qualifies, update it as soon as possible.

Why this update deserves attention

Security updates can feel routine. Many of us see the notification and decide to deal with it later. This time is different. Apple confirmed the flaw was actively exploited. That means attackers already know how to use it. Running older software gives them a window of opportunity. Updating closes that window.

How to update your iPhone or iPad

Updating takes only a few minutes.

  • Go to Settings
  • Tap General
  • Tap Software Update
  • If an update appears, tap Download and Install
  • Turn on Automatic Updates so you do not miss future fixes

Keep your device connected to Wi-Fi and power during the process.

APPLE WARNS MILLIONS OF IPHONES ARE EXPOSED TO ATTACK

Once you reach this screen on your iPhone, tap Update Now to install Apple’s latest security fix immediately. (Kurt “CyberGuy” Knutsson)

How to update your Mac

  • Click the Apple menu in the upper left corner
  • Choose System Settings or System Preferences
  • Select General
  • Click Software Update
  • If an update appears, select Restart Now or Update Tonight

Your Mac may restart during the process. Keep it plugged in and connected to the internet until the update finishes.

Mac users will see options like Update Tonight or Restart Now, and installing this update closes a flaw already exploited in attacks. (Kurt “CyberGuy” Knutsson)

Advertisement

How to update Apple Watch

  • Keep your Watch on its charger and near your iPhone
  • Open the Watch app on your iPhone
  • Tap General
  • Tap Software Update
  • Tap Download and Install if available

Your Watch will restart during the update.

Your Apple Watch also receives critical security fixes, so keep it on the charger and update it just like your iPhone. (Kurt “CyberGuy” Knutsson)

How to update Apple TV

  • Open Settings on Apple TV
  • Go to System
  • Select Software Updates
  • Choose Update Software
  • Select Download and Install

Stay connected to power and Wi Fi until the update completes.

How to update Safari

Safari updates are included with macOS updates.

  • Go to the Apple menu
  • Click System Settings
  • Select General
  • Click Software Update

If Safari appears separately, click Update Now and restart your Mac.

How to update your Apple Vision Pro

  • Put on your Vision Pro and open the Settings app.
  • Select General from the sidebar.
  • Tap Software Update.
  • If an update appears for visionOS 26.3, choose Download and Install.
  • Make sure your Vision Pro stays charged and connected to Wi-Fi until the update completes.

MALICIOUS MAC EXTENSIONS STEAL CRYPTO WALLETS AND PASSWORDS

Ways to stay safe

Installing this update is the most important step. Still, there are additional habits that strengthen your protection.

  • Turn on automatic updates for every Apple device
  • Restart devices regularly to clear temporary processes
  • Avoid clicking unsolicited links or attachments, and use strong antivirus software. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
  • Remember, Apple threat notifications will never ask for passwords or verification codes
  • Be cautious when viewing HTML-formatted emails in Apple Mail
  • Consider enabling Lockdown Mode if you face a higher risk

Cybercriminals rely on hesitation. They count on us assuming we will get to the update later.

Kurt’s key takeaways

Apple moved fast to fix this vulnerability, and that is reassuring. Now it is up to us to do our part. I get it. Updates interrupt your day. They force a restart. They rarely feel urgent. But here is the thing. Installing updates is still the simplest and most effective way to protect your device from active threats. A few minutes now can prevent a serious security problem later.

What is your biggest reason for delaying updates, and has it ever cost you? Let us know by writing to us at Cyberguy.com.

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Copyright 2026 CyberGuy.com. All rights reserved.

Continue Reading

Technology

Meta’s new deal with Nvidia buys up millions of AI chips

Published

on

Meta’s new deal with Nvidia buys up millions of AI chips

Meta has struck a multiyear deal to expand its data centers with millions of Nvidia’s Grace and Vera CPUs and Blackwell and Rubin GPUs. While Meta has long been using Nvidia’s hardware for its AI products, this deal “represents the first large-scale Nvidia Grace-only deployment,” which Nvidia says will deliver “significant performance-per-watt improvements in [Meta’s] data centers.” The deal also includes plans to add Nvidia’s next-generation Vera CPUs to Meta’s data centers in 2027.

Meta is also working on its own in-house chips for running AI models, but according to the Financial Times, it has run into “technical challenges and rollout delays” with its chip strategy. Nvidia is also dealing with concerns about depreciation and chip-back loans used to finance AI buildouts, as well as the pressure of competition. CNBC notes that Nvidia’s stock dropped four percent after a November report about Meta considering using Google’s Tensor chips for AI, and late last year, AMD announced chip arrangements with both OpenAI and Oracle.

Nvidia and Meta did not disclose how much the deal cost, but this year’s AI spending from Meta, Microsoft, Google, and Amazon is estimated to cost more than the entire Apollo space program.

Continue Reading

Trending