Android › Module 1 › Lesson 3
Banking Trojans
How Android banking malware overlays fake logins and drains accounts
Opening
Your bank app opens—but it is not your bank
Android banking trojans often wait until you launch a financial app, then draw an overlay, phishing WebView, or accessibility-driven UI that steals passwords, OTPs, and sometimes locks you out of your own device. They are not sci-fi. They are industrial crimeware sold in underground markets.
1. Typical Infection Path
Dropper APK (fake update, utility, porn app, “security tool”) → requests Accessibility / notification / SMS rights → hides its icon → watches for banking packages → shows a fake login or intercepts one-time codes. Some families also steal cookies, contacts, or 2FA apps. Others enroll as a device admin so they are hard to uninstall.
2. Defenses That Matter
No random APKs
Most banking malware still arrives outside careful Play installs.
Refuse weird Accessibility grants
A game or cleaner rarely needs full Accessibility control.
OS + bank app updates
Patches close abuse of overlays and permission quirks.
Transaction alerts
Instant bank SMS/push alerts catch drains faster than hoping malware self-reports.
Unexpected password prompt = stop
If your bank suddenly asks to “re-login” with a screen that feels off, force-close, check installed apps, and open the bank only from the verified icon—or call the bank on the card number.
Knowledge Check
What do many Android banking trojans abuse?
Multiple choice
Knowledge Check
True or False: Banking trojans often hide their icons after install.
True or False
Knowledge Check
Which permission request should make you especially suspicious?
Multiple choice