<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

New Android Banking Trojan Silences Phones While Stealing Crypto

Beware of 'BankBot-YNRK,' an Android Trojan impersonating Indonesia's digital ID app, stealing crypto and banking data in SE Asia.
Content Team

Security researchers discovered a sophisticated Android banking Trojan called "BankBot-YNRK" targeting users in Indonesia and Southeast Asia. The malware disguises itself as Indonesia's official digital ID app, tricking users into installing it from outside Google Play Store.

Once installed, the Trojan mutes all device alerts—calls, notifications, messages—to avoid detection while stealing cryptocurrency wallet data, banking credentials, and personal information. It specifically targets devices running Android 13 and earlier, exploiting accessibility features to gain complete remote control.

The malware takes real-time screenshots of banking and crypto wallet apps to map their interfaces, then automates fraudulent transactions. It targets Bitcoin, Ethereum, Litecoin, and Solana wallets, extracting seed phrases and private keys without user knowledge.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo