Technology
Updated Android malware can hijack calls you make to your bank
Do you remember those TV shows where the villain gets defeated in one season but comes back even stronger in the next? Think “Stranger Things” on Netflix. The malware we’re talking about here is just like that. It’s called FakeCalls, and every time researchers figure out how it infects devices, it evolves with new ways to hide.
Earlier this year, it was reported to be impersonating large financial institutions, and now security researchers have discovered that the malware has gone through another upgrade. It can even hijack the calls you make to your bank using your Android phone.
ENTER CYBERGUY’S $500 HOLIDAY GIFT CARD SWEEPSTAKES
What you need to know
FakeCalls is a banking trojan that focuses on voice phishing, where victims are deceived through fraudulent calls impersonating banks and are asked to share sensitive information. Earlier versions did this by prompting users to call the bank from within an app that impersonated the financial institution, as reported by Bleeping Computer. However, the latest version, analyzed by Zimperium, sets itself as the default call handler.
The default call handler app manages incoming and outgoing calls, allowing users to answer, reject or initiate calls. Giving these permissions to a malicious app, as you can imagine, carries serious risks.
When a user gives the app permission to set itself as the default call handler, the malware gets the green light to intercept and mess with both outgoing and incoming calls. It even shows a fake call interface that looks just like the real Android dialer, complete with trusted contact info and names. This level of deception makes it really tough for victims to see what’s happening.
“When the compromised individual attempts to contact their financial institution, the malware redirects the call to a fraudulent number controlled by the attacker,” explains the new Zimperium report. “The malicious app will deceive the user, displaying a convincing fake UI that appears to be the legitimate Android’s call interface showing the real bank’s phone number.”
“The victim will be unaware of the manipulation, as the malware’s fake UI will mimic the actual banking experience, allowing the attacker to extract sensitive information or gain unauthorized access to the victim’s financial accounts,” the report added.
ANDROID BANKING TROJAN EVOLVES TO EVADE DETECTION AND STRIKE GLOBALLY
The malware can also steal your data
This malware not only hijacks your calls but can also steal your data. It gets access to Android’s Accessibility permissions, which basically gives it free rein to do whatever it wants. The developer of the malware has also added several new commands, including the ability to start livestreaming the device’s screen, take screenshots, unlock the device if it’s locked and temporarily turn off auto-lock. It can also use accessibility features to mimic pressing the home button, delete images specified by the command server, and access, compress and upload photos and thumbnails from storage, especially from the DCIM folder.
ANDROID BANKING TROJAN MASQUERADES AS GOOGLE PLAY TO STEAL YOUR DATA
6 ways to protect yourself from FakeCalls malware
1) Have strong antivirus software: Android has its own built-in malware protection called Play Protect, but the FakeCalls malware proves it’s not enough. Historically, Play Protect hasn’t been 100% foolproof at removing all known malware from Android phones. Also, avoid clicking on any links in messages or emails that seem suspicious. The best way to protect yourself from clicking malicious links that install malware that may get access to your private information is to have antivirus protection installed on all your devices. This can also alert you of any phishing emails or ransomware scams.
Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android and iOS devices.
2) Download apps from reliable sources: It’s important to download apps only from trusted sources, like the Google Play Store. The FakeCalls malware infects your phone when you download an app from an unknown link. As an Android user, you should only download apps from the Play Store, which has strict checks to prevent malware and other harmful software. Avoid downloading apps from unknown websites or unofficial stores, as they pose a higher risk to your personal data and device. Also, never trust download links that you receive through SMS.
3) Be cautious with app permissions: Always review the permissions requested by apps before installation. If an app requests access to features that seem unnecessary for its function, it could be a sign of malicious intent. Do not give any app Accessibility permissions unless you really need to. Avoid granting permissions that could compromise your personal data.
4) Regularly update your device’s operating system and apps: Keeping your software up to date is crucial, as updates often include security patches for newly discovered vulnerabilities that could be exploited by malware like FakeCalls.
5) Monitor financial activity regularly: Check your bank and credit card statements often for unauthorized transactions. Set up alerts for any account activity, which can notify you immediately if suspicious activity occurs.
6) Limit sensitive transactions on mobile: Whenever possible, avoid performing high-risk transactions (like large money transfers) on your mobile device, especially if you’re in public or connected to unsecured Wi-Fi. Use a secure computer or contact your bank directly from a verified number.
THE HIDDEN COSTS OF FREE APPS: YOUR PERSONAL INFORMATION
Kurt’s key takeaway
Hackers are constantly upgrading their tactics and finding clever ways to hack your devices and scam you out of your hard-earned money. I really think Android phone manufacturers and Google need to step up their game on security to help keep users from getting hacked so often. I don’t see the same level of malware affecting iPhones.
How comfortable are you using your mobile phone for financial transactions, and what would make you feel safer? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover. Follow Kurt on his social channels:
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
Google reveals quantum computing chip with ‘breakthrough’ achievements
Google’s quantum computing lab just achieved a major milestone. On Monday, the company revealed that its new quantum computing chip, Willow, is capable of performing a computing challenge in less than five minutes — a process Google says would take one of the world’s fastest supercomputers 10 septillion years, or longer than the age of the universe.
Along with more powerful performance, researchers also found a way to reduce errors, something Google calls “one of the greatest challenges in quantum computing.” Instead of bits, which represent either 1 or 0, quantum computing uses qubits, a unit that can exist in multiple states at the same time, such as 1, 0, and anything in between.
As noted by Google, qubits are prone to errors because they “have a tendency to rapidly exchange information with their environment.” However, Google’s researchers discovered a way to reduce errors by introducing more qubits to a system and were able to correct them in real time. Their findings were published in Nature.
“This historic accomplishment is known in the field as ‘below threshold’ — being able to drive errors down while scaling up the number of qubits,” Google Quantum AI founder Hartmut Neven writes on Google’s blog. “You must demonstrate being below threshold to show real progress on error correction, and this has been an outstanding challenge since quantum error correction was introduced by Peter Shor in 1995.”
Willow, which has 105 qubits, “now has best-in-class performance,” according to Neven. Microsoft, Amazon, and IBM are working on quantum computing systems of their own.
Google’s next goal is to perform a first “useful, beyond-classical” computation that is both “relevant to a real-world application” and one that typical computers can’t achieve. Going forward, Neven says quantum technology will be “indispensable” for collecting AI training data, eventually helping to “discover new medicines, designing more efficient batteries for electric cars, and accelerating progress in fusion and new energy alternatives.”
Technology
The Suicide Squad game’s final season is coming less than a year after launch
Suicide Squad: Kill the Justice League only came out in February, but the game’s final season, which starts tomorrow, is going to be its last. Season 4 Episode 7 launches on Tuesday, and Episode 8, which is set to release on January 14th, 2025, will “serve as the last seasonal Episode for Suicide Squad: Kill the Justice League,” developer Rocksteady announced on Monday.
After the release of the final content, the game will still be available to play online, according to a WB Games FAQ. But the game is also getting an offline mode tomorrow — which had been previously announced, though without a specific date beyond “2024” — that will let you play the main story and all seasonal story mission content without an internet connection.
The game has had a troubled history. The game was originally set to release in 2022 before being delayed multiple times. And a largely unsuccessful launch — in our review, we said the game “hides its brash personality under a generic looter shooter” — resulted in Warner Bros. Discovery announcing in May that it would be taking a $200 million loss on the game.
Technology
Router VPNs vs device VPNs: Which privacy solution is best for you?
VPNs (virtual private networks) are a powerful tool for securing your internet connection. They protect your data by encrypting it, making it harder for hackers or even your internet service provider (ISP) to see what you’re doing online. But how should you set up a VPN? Should you install it on each device or run it on your home network through a router? We will break down the pros and cons of both methods to help you make the right decision.
GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE
How VPNs work
VPNs operate through two primary mechanisms: IP address masking and data encryption. When you connect to a VPN, it hides your real IP address by assigning you a new one from their server network, effectively preventing websites and cyber criminals from tracking your location or identifying you based on your IP address.
Simultaneously, VPNs encrypt all data transmitted between your device and the internet, rendering it unreadable to anyone who might attempt to intercept it. This encryption process ensures that sensitive information, such as credit card details, remains confidential throughout your online activities. By combining these two powerful features, VPNs create a secure tunnel for your internet traffic, significantly enhancing your online privacy and security.
VPN on devices vs. router: What’s the difference?
Understanding the difference between using a VPN on individual devices vs. setting it up on your router is crucial for maximizing your online security and privacy.
VPN on a device
Most people are familiar with using a VPN app on their phone, laptop or tablet. In this setup, the device connects directly to the internet through the VPN, keeping that device’s internet activity secure.
VPN on a router
With a VPN router, instead of installing a VPN on each device, the router connects to the VPN. This means every device connected to your Wi-Fi – whether a smartphone, laptop, gaming console or even a smart TV – automatically uses the VPN, even if that device doesn’t support VPN apps.
TOP ROUTERS FOR BEST SECURITY 2024
Why use a VPN router?
There are several advantages to running a VPN directly on your router.
1) Protect all the devices on your network
A VPN router ensures that every device on your network is protected, even those that don’t support VPNs, like smart home devices or certain game consoles. Once the router is set up with a VPN, it encrypts the internet traffic of all connected devices.
2) Set it and forget it
Installing or managing VPN software on every device is unnecessary with a VPN router. Once the router is configured, you can sit back and enjoy a protected internet connection across your entire home network. However, it’s a good idea to occasionally check that the connection is working properly using tools like DNS leak tests.
3) Increased privacy
Using a VPN prevents your ISP from seeing which websites or services you’re using. This is particularly useful if you’re concerned about privacy or want to access geo-restricted content, such as streaming services like Netflix or gaming platforms.
Are there any downsides to VPN routers?
While VPN routers are convenient, they do come with a few potential drawbacks.
1) Cost
Most basic routers provided by your ISP don’t support VPN connections. You’ll likely need to purchase a more advanced, VPN-compatible router, which can be pricier, starting at around $50 and going much higher for premium models.
2) Speed and performance
Encrypting all the traffic in your home network requires processing power. If you have a lot of devices connected at once, a primary router might struggle to keep up. In this case, a higher-end router with more processing power is recommended.
3) Less flexibility
When you use a VPN app on a device, switching server locations, adjusting security settings or choosing different VPN protocols is easy. Making these changes on a VPN router requires logging into the router’s settings, which can be more time-consuming and complicated.
DON’T TOSS YOUR OLD INTERNET ROUTER UNTIL YOU DO THIS
How to set up a VPN on a router
Setting up a VPN on your router may seem complex, but it significantly enhances your digital security, especially when paired with a robust router. Here’s how to approach this process.
Choose a compatible VPN service: Select a VPN provider that supports router installations. Look for services that offer comprehensive guides and customer support to assist you through the setup.
Select the right router: Ensure your router is VPN compatible and has strong security features. Opt for routers that support the latest Wi-Fi encryption standards, such as WPA3, and have built-in firewalls to protect against external threats. This will provide a solid foundation for your VPN connection.
Install the VPN: Follow your VPN provider’s step-by-step instructions to configure the service on your router. This typically involves entering your login credentials, installing necessary certificates and selecting a server location.
Test your connection: Once configured, verify that your VPN is functioning correctly by testing the connection. Ensure that all devices connected to the router are protected by the VPN.
Leverage additional security features: Take advantage of your router’s features such as guest networks and parental controls to enhance security further. A separate guest network prevents unauthorized access to your main network, while regular firmware updates from the manufacturer help mitigate vulnerabilities.
By integrating these steps, you not only set up a VPN but also fortify your home network against potential cyber threats.
BEST VPNs FOR BROWSING THE WEB PRIVATELY 2024
Should you use a VPN on a router or device?
When to use a VPN on a device:
- If you only need protection on a few devices, installing the VPN directly on your devices might be easier if you mostly use the internet on your phone and laptop.
- If you want flexibility, using a VPN app lets you quickly switch servers, change settings or disconnect the VPN when needed.
When to use a VPN on a router:
- If you have many devices, a VPN router is ideal if you have many devices connected to your Wi-Fi, especially if some of those devices don’t support VPN apps.
- If you want whole-home protection, a VPN router protects every device on your network, providing seamless security without the need to install apps on each one.
Find the perfect VPN software
When selecting a VPN on a device, you’ll want to choose trusted providers known for robust encryption and no-log policies to ensure your privacy. Whether for sensitive tasks or everyday use, reputable VPN services will boost your security and speed. For the best VPN software, see my expert review of the best VPNs for browsing the web privately on your Windows, Mac, Android and iOS devices.
WHY YOU SHOULD BE USING A VPN TO SAFEGUARD YOUR STOCK TRADING ACTIVITIES
Both VPN routers and VPN apps have their own strengths, and the right choice depends on your specific needs. A VPN router might be the way to go if you’re looking for convenience and whole-home protection. But if you prefer flexibility and more control over individual devices, sticking with a VPN app might suit you better. Either way, a VPN is a great step toward protecting your privacy and securing your online activities.
What aspects of online privacy and security are most important to you when browsing the internet at home? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter. Ask Kurt a question or let us know what stories you’d like us to cover.
Follow Kurt on his social channels:
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2024 CyberGuy.com. All rights reserved.
Kurt’s key takeaways
-
Technology1 week ago
Elon Musk targets OpenAI’s for-profit transition in a new filing
-
News1 week ago
Rassemblement National’s Jordan Bardella threatens to bring down French government
-
Technology1 week ago
9 ways scammers can use your phone number to try to trick you
-
World1 week ago
Georgian PM praises country's protest crackdown despite US condemnation
-
World7 days ago
Freedom is permanent for Missourian described as the longest-held wrongly incarcerated woman in US
-
Technology3 days ago
Struggling to hear TV dialogue? Try these simple fixes
-
Business23 hours ago
OpenAI's controversial Sora is finally launching today. Will it truly disrupt Hollywood?
-
World6 days ago
Brussels denies knowledge of Reynders's alleged money laundering