Sneaky Multi-Stage Android Malware Spreads Banking Trojans in Google Play

Tara Seals

Another set of malicious mobile apps has made it into the official Google Play app store, which are notable thanks to their multi-stage architecture and the encryption they use to stay under the radar.

Detected by ESET security systems as Android/TrojanDropper.Agent.BKY, these apps form a new family of multi-stage Android malware, which use a delayed onset of malicious activity to masquerade as legitimate—there are no immediate red flags for the user to look for, in other words. After being downloaded and installed, these apps do not request any suspicious permissions and they even mimic the activity the user expects them to exhibit.

