Connect with us

Technology

New Android malware can empty your bank account in seconds

Published

on

New Android malware can empty your bank account in seconds

NEWYou can now listen to Fox News articles!

Android users have been dealing with a steady rise in financial malware for years. Threats like Hydra, Anatsa and Octo have shown how attackers can take over a phone, read everything on the screen and drain accounts before you even notice anything wrong. Security updates have helped slow some of these strains, but malware authors keep adapting with new tricks. 

The latest variant spotted in circulation is one of the most capable yet. It can silence your phone, take screenshots of banking apps, read clipboard entries, and even automate crypto wallet transactions. This threat is now known as Android BankBot YNRK, and it is far more advanced than typical mobile malware.

Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter

How the malware infiltrates devices

HOW ANDROID MALWARE LETS THIEVES ACCESS YOUR ATM CASH

Advertisement

Android banking malware is getting harder to spot as attackers use new tricks to take over phones and drain accounts. (Thomas Trutschel/Photothek via Getty Images)

BankBot YNRK hides inside fake Android apps that appear legitimate when installed. In the samples analyzed by researchers at Cyfirma, the attackers used apps that impersonated official digital ID tools. Once installed, the malware begins profiling the device by collecting details such as brand, model and installed apps. It checks whether the device is an emulator to avoid automated security analysis. It also maps known models to screen resolutions, which helps it tailor its behavior to specific phones.

To blend in, the malware can disguise itself as Google News. It does this by changing its app name and icon, then loading the real news.google.com site inside a WebView. While the victim believes the app is genuine, the malware quietly runs its background services.

One of its first actions is to mute audio and notification alerts. This prevents victims from hearing incoming messages, alarms or calls that could signal unusual account activity. It then requests access to Accessibility Services. If granted, this allows the malware to interact with the device interface just like a user. From that point onward, it can press buttons, scroll through screens and read everything displayed on the device.

BankBot YNRK also adds itself as a Device Administrator app. This makes it harder to remove and helps it restart itself after a reboot. To maintain long-term access, it schedules recurring background jobs that relaunch the malware every few seconds as long as the phone is connected to the internet.

Advertisement

What does the malware steal

Once the malware receives commands from its remote server, it gains near-complete control of the phone. It sends device information and installed app lists to the attackers, then receives a list of financial apps it should target. This list includes major banking apps used in Vietnam, Malaysia, Indonesia and India, along with several global cryptocurrency wallets.

With Accessibility permissions enabled, the malware can read everything shown on the screen. It captures UI metadata such as text, view IDs and button positions. This helps it reconstruct a simplified version of any app’s interface. Using this data, it can enter login details, swipe through menus or confirm transfers. It can also set text inside fields, install or remove apps, take photos, send SMS, turn call forwarding on and open banking apps in the background while the screen appears inactive.

In cryptocurrency wallets, the malware acts like an automated bot. It can open apps such as Exodus or MetaMask, read balances and seed phrases, dismiss biometric prompts, and carry out transactions. Because all actions happen through Accessibility, the attacker never needs your passwords or PINs. Anything visible on the screen is enough.

The malware also monitors the clipboard, so if users copy OTPs, account numbers or crypto keys, the data is immediately sent to the attackers. With call forwarding enabled, incoming bank verification calls can be silently redirected. All of these actions happen within seconds of the malware activating.

BankBot YNRK hides inside fake apps that look legitimate, then disguises itself as Google News while it runs in the background. (AP Photo/Don Ryan, File)

Advertisement

7 steps you can take to stay safe from banking malware

Banking trojans are getting harder to spot, but a few simple habits can reduce the chances of your phone getting compromised. Here are seven practical steps that help you stay protected. 

FBI WARNS OVER 1 MILLION ANDROID DEVICES HIJACKED BY MALWARE

1) Install strong antivirus software

Strong antivirus software helps catch trouble early by spotting suspicious behavior before it harms your Android device or exposes your data. It checks apps as you install them, alerts you to risky permissions and blocks known malware threats. Many top antivirus options also scan links and messages for danger, which adds an important layer of protection when scams move fast.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Advertisement

2) Use a data-removal service to shrink your digital footprint

Data brokers quietly collect and sell your personal details, which helps scammers target you with more convincing attacks. A reputable data-removal service can find and delete your information from dozens of sites so that criminals have less to work with. This reduces spam, phishing attempts and the chances of ending up on a malware attack list.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

3) Install apps only from trusted sources

Avoid downloading APKs from random websites, forwarded messages or social media posts. Most banking malware spreads through sideloaded apps that look official but contain hidden code. The Play Store is not perfect, but it offers scanning, app verification and regular take-downs that greatly reduce the risk of installing infected apps.

Advertisement

4) Keep your device and apps updated

System updates often patch security issues that attackers exploit to bypass protections. Updating your apps is just as important, since outdated versions may contain weaknesses. Turn on automatic updates so that your device stays protected without you having to check manually.

5) Use a strong password manager

A password manager helps you create long, unique passwords for every account. It also saves you from typing passwords directly into apps, which reduces the chance of malware capturing them from your clipboard or keystrokes. If one password gets exposed, the rest of your accounts remain safe.

Next, see if your email has been exposed in past breaches. Our No. 1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials. 

Once active, the malware can read your screen, steal financial data, automate crypto transfers and intercept OTPs within seconds. (Kurt “CyberGuy” Knutsson)

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com

Advertisement

6) Enable two-factor authentication wherever possible

2FA adds a confirmation step through an OTP, authenticator app or hardware key. Even if attackers steal your login details, they still need this second step to get in. It cannot stop malware that takes over your device, but it significantly limits how far an attacker can go with stolen credentials.

GOOGLE ISSUES WARNING ON FAKE VPN APPS

7) Review app permissions and installed apps regularly

Malware often abuses permissions such as Accessibility or Device Admin because they allow deep control over your phone. Check your settings to see which apps have these permissions and remove anything that looks unfamiliar. Also, look through your installed apps and uninstall any tool or service you do not remember adding. Regular reviews help you spot threats early before they can steal data.

Kurt’s key takeaway

BankBot YNRK is one of the most capable Android banking threats discovered recently. It combines device profiling, strong persistence, UI automation and data theft to gain full control over a victim’s financial apps. Because much of its activity relies on Accessibility permissions, a single tap from the user can give attackers complete access. Staying safe means avoiding unofficial APKs, reviewing installed apps regularly and being cautious of any sudden request to enable special permissions.

Do you think Android phone makers like Samsung or Google are doing enough to protect you from malware? Let us know by writing to us at Cyberguy.com

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter

Copyright 2025 CyberGuy.com.  All rights reserved.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Shokz’s bassy OpenRun Pro 2 are $40 off thanks to a new Mother’s Day promo

Published

on

Shokz’s bassy OpenRun Pro 2 are  off thanks to a new Mother’s Day promo

If you’re looking to pick up a pair of open-ear headphones for yourself — or your mom — Shokz is running a Mother’s Day sale. Now through May 10th, the company’s best pair of bone conduction headphones, the OpenRun Pro 2, are available from Amazon, Best Buy, and Shokz for around $139.95 ($40 off), their lowest price of the year. If you purchase direct, you’ll also receive a free waist bag (a $29.99 value).

While traditional headphones tend to block out the world, open-style headphones provide a safer alternative, letting you listen to music and podcasts while remaining vigilant. After testing the OpenRun Pro 2, The Verge’s Victoria Song said using them felt “like the stars finally aligning.” Unlike many open-ear headphones, they don’t skimp on bass or clarity thanks to a dedicated air conduction speaker, though they still won’t rival a traditional pair of in-ears when it comes to sound quality. Still, they’re more comfortable than earlier Shokz models, with flexible ear hooks and a lightweight neckband that creates a secure, natural fit, even for those who wear glasses.

The fact that the Pro 2 vibrate significantly less than other models is another highlight, as is battery life. They offer up to 12 hours on a single charge, which was enough for us to go nearly a week without plugging them in (they charge incredibly fast via USB-C, too). They also include AI-powered noise cancellation for calls (though results were mixed in our testing) and an IP55 rating, making them well-suited for both sweaty workouts and outdoor use.

Other Shokz deals to consider

Continue Reading

Technology

United Arab Emirates plans AI-run government within two years

Published

on

United Arab Emirates plans AI-run government within two years

NEWYou can now listen to Fox News articles!

The United Arab Emirates just made one of the most aggressive moves yet in the global AI race. The country says it will integrate agentic artificial intelligence across half of its government operations within two years.

For context: Most governments are still debating whether to use AI.  This plan puts speed and execution front and center and goes in the opposite direction of how governments typically handle major technology changes.

If it works, the UAE could offer a preview of how AI may reshape public services far beyond the Middle East. If it runs into problems, it could also highlight the risks of moving this fast when government decisions, personal data and public trust are all involved.

Sign up for my FREE CyberGuy Report

Advertisement

UAE AMBASSADOR YOUSEF AL OTAIBA: US AND UAE FORGE GROUNDBREAKING HIGH-TECH PARTNERSHIP BASED ON AI

UAE leaders meet to outline a plan that would bring Agentic AI into core government decision-making and operations. (Dubai Media Office)

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

What agentic AI means for the UAE government

Agentic AI refers to systems that can analyze information, make decisions and take action with minimal human input. In this model, AI can process requests, adjust workflows and improve outcomes in real time. It can also carry out certain government tasks from start to finish, instead of only suggesting what a person should do next.

So, how would that show up in everyday ways? Think faster permit approvals, automated public services or systems that respond instantly to changes in demand. Instead of waiting for human bottlenecks, processes move continuously.

FOX NEWS AI NEWSLETTER: TRUMP ADMIN UNVEILS GROUNDBREAKING TOOL ‘SUPERCHARGING’ GOV’T EFFICIENCY IN AI

According to the announcement, AI will act more like an operational partner than a tool. That marks a change in how governments think about technology.

Advertisement

How the UAE plans to roll out AI across government

There is also a clear structure behind the rollout. The UAE has put a detailed plan in place with clear expectations from the start. Every ministry and government entity will be evaluated based on how quickly it adopts AI, how well it implements those systems and how effectively it redesigns workflows around them.

Oversight will come from Mansour bin Zayed Al Nahyan, a senior government leader who plays a key role in the country’s executive decision-making. Day-to-day execution will be led by a task force chaired by Mohammad Al Gergawi, a longtime cabinet minister focused on government modernization.

How AI will change government jobs in the UAE

One of the biggest parts of this plan has less to do with machines and more to do with people. Every federal employee will receive AI training. The goal is to build a workforce that can work alongside intelligent systems rather than compete with them.

That matters because large-scale automation often raises concerns about job loss. The UAE is taking a different angle by focusing on reskilling and adaptation. If it works, it could become a model that other countries try to follow. If it struggles, it will highlight how difficult workforce transformation can be at scale.

Why the UAE is moving so fast on AI in government

This move fits into a broader strategy. The UAE has spent years positioning itself as a tech-forward economy. By embedding AI into government operations, the country hopes to improve efficiency, reduce delays and deliver faster services to residents and businesses.

Advertisement

It also sends a signal globally. The UAE wants to set the benchmark for how governments use AI in a big way. That puts pressure on other countries, including the United States, to rethink how quickly we adopt similar technologies.

The UAE plans to use agentic AI to help analyze information, make decisions and carry out tasks across a wide range of government services. (Kurt “CyberGuy” Knutsson)

Concerns about AI in government are already growing

For all the excitement, this kind of rollout raises real concerns. Critics point to accountability as one of the biggest questions. When AI systems start making decisions inside government, it can become harder to understand who is responsible when something goes wrong. Was it the system, the developer or the agency using it?

JOBS THAT ARE MOST AT RISK FROM AI, ACCORDING TO MICROSOFT

Privacy is another sticking point. Government systems already handle sensitive personal data. Expanding AI across those systems could increase how much data is collected, analyzed and stored, which makes some experts uneasy.

Advertisement

There is also the issue of bias. AI models learn from data, and if that data has gaps or flaws, the outcomes can reflect that. In a government setting, that could affect access to services, approvals or enforcement decisions in ways that are not always obvious.

Then there is trust. Even if the systems work as intended, people may still hesitate to accept decisions made by machines, especially when those decisions affect their daily lives.

Supporters argue that these risks can be managed with strong oversight and transparency. Still, critics say the speed of this rollout leaves little room for error, and that is where the debate is likely to intensify.

What this means to you

Even if you do not live in the UAE, this push has real implications. First, it raises expectations. When one government proves it can deliver faster services with AI, people elsewhere will start asking why theirs cannot.

Second, it accelerates the global AI race. Governments will need to balance speed with privacy, security and oversight. Third, it highlights a growing reality. AI is moving into decision-making roles beyond basic support functions. That changes how systems are built and how accountability works.

Advertisement

You may start to see similar experiments here in the United States, especially at the state or city level, where innovation can happen faster.

Take my quiz: How safe is your online security?

Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my quiz here: CyberGuy.com

Kurt’s key takeaways

The UAE is betting big on a future in which AI plays a central role in how its government operates. The timeline is aggressive, and the scope is hard to ignore. What stands out most is how quickly this is moving from concept to execution. At the same time, the questions are just as big as the opportunity. Who is accountable when AI makes a decision? How much data is being used behind the scenes? And how much trust are people willing to place in systems they cannot fully see? This could become a model that other governments try to follow. It could also expose real challenges around transparency and control. Either way, it is a clear signal that AI is moving deeper into systems that affect our everyday lives.

The initiative is set to expand AI across multiple agencies, with a focus on faster services, improved efficiency and real-time operations. (Kurt “CyberGuy” Knutsson)

If AI can start making real-time decisions inside government systems, how comfortable are you with that level of automation showing up in your everyday life? Let us know by writing to us at Cyberguy.com

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com.  All rights reserved.  

Advertisement
Continue Reading

Technology

Reggie Fils-Aimé says Amazon once asked Nintendo to break the law

Published

on

Reggie Fils-Aimé says Amazon once asked Nintendo to break the law

“Literally, we stopped selling to Amazon, and it’s because I wasn’t going to do something illegal. I wasn’t going to do something that would put at risk the relationship we have with other retailers. But it also set the stage to say, look, you’re not going to push me around. This is the way we do business. And so that’s how, over time, you build respect.”

Continue Reading
Advertisement

Trending