{"id":2687,"date":"2021-05-13T20:42:49","date_gmt":"2021-05-14T01:42:49","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2687"},"modified":"2021-05-13T20:42:50","modified_gmt":"2021-05-14T01:42:50","slug":"teabot-a-dangerous-malware-targeting-banks","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/","title":{"rendered":"TeaBot &#8211; A dangerous malware targeting banks"},"content":{"rendered":"\n<p>Cleafy, a company specialized in cyber security, announced that it has discovered a new malicious program or malware called TeaBot, a Trojan designed to affect mobile devices with Android operating system that this year has already attacked at least 60 European banks due to its ability to steal victims&#8217; credentials, access their SMS and remotely control the phone.<\/p>\n\n\n\n<p>This threat was initially discovered in January, and on March 29 the first injection against Italian banks was detected, while at the beginning of May it began to expand and has also affected entities in Belgium and the Netherlands. The &#8216;malware&#8217; has managed to extract user information from more than 60 European banks, and in fact includes text in different languages, among which is Spanish and also Italian and German. TeaBot, which does not belong to any known &#8216;malware&#8217; family, abuses the Accessibility Services of the Android operating system, a technique commonly used by banking Trojans.<\/p>\n\n\n\n<p>On a technical level it is very similar to Flubot. TeaBot hides itself under the name DHL, UPS, VLC MediaPlayer or Mobdro, that is, it pretends to be other applications. Once we install it, it asks us for accessibility permission and, when it has it, we have already fallen into the trap.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">what are the capabilities that TeaBot malware can do<\/h2>\n\n\n\n<p>Once the Trojan manages to infect the user&#8217;s device, it manages to manipulate the system&#8217;s screen overlay functions in order to obtain the credentials of the accounts in digital banking services and the credit card information of the victims.Undoubtedly, this malware is capable of many things and that is why it is very dangerous.<\/p>\n\n\n\n<p><strong><em>\u25b8Send and intercept SMS messages<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Read phone status<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Modify sound settings to silence the phone<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Show a pop-up about other apps so that we accept permissions<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Delete apps without permission<\/em><\/strong><\/p>\n\n\n\n<p>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/adb-miner-malware-that-mines-on-android-devices\/\">ADB Miner \u2013 Malware that mines on Android Devices<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/what-kind-of-spyware-does-android-face\/\">What kind of spyware does Android face<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cleafy, a company specialized in cyber security, announced that it has discovered a new malicious program or malware called TeaBot, a Trojan designed to affect mobile devices with Android operating system that this year has already attacked at least 60 European banks due to its ability to steal victims&#8217; credentials, access their SMS and remotely [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2688,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2687","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TeaBot - A dangerous malware targeting banks - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Bank data is always a desired asset by cybercriminals and this is how this threat called TeaBot arrives, which we will see and analyze today.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TeaBot - A dangerous malware targeting banks - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Bank data is always a desired asset by cybercriminals and this is how this threat called TeaBot arrives, which we will see and analyze today.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-14T01:42:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-05-14T01:42:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Malware-Tea.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"516\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"TeaBot &#8211; A dangerous malware targeting banks\",\"datePublished\":\"2021-05-14T01:42:49+00:00\",\"dateModified\":\"2021-05-14T01:42:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/\"},\"wordCount\":323,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Malware-Tea.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/\",\"name\":\"TeaBot - A dangerous malware targeting banks - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Malware-Tea.jpg\",\"datePublished\":\"2021-05-14T01:42:49+00:00\",\"dateModified\":\"2021-05-14T01:42:50+00:00\",\"description\":\"Bank data is always a desired asset by cybercriminals and this is how this threat called TeaBot arrives, which we will see and analyze today.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Malware-Tea.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Malware-Tea.jpg\",\"width\":900,\"height\":516},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/teabot-a-dangerous-malware-targeting-banks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TeaBot &#8211; A dangerous malware targeting banks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TeaBot - A dangerous malware targeting banks - Truxgo Server Blog","description":"Bank data is always a desired asset by cybercriminals and this is how this threat called TeaBot arrives, which we will see and analyze today.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/","og_locale":"es_MX","og_type":"article","og_title":"TeaBot - A dangerous malware targeting banks - Truxgo Server Blog","og_description":"Bank data is always a desired asset by cybercriminals and this is how this threat called TeaBot arrives, which we will see and analyze today.","og_url":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-14T01:42:49+00:00","article_modified_time":"2021-05-14T01:42:50+00:00","og_image":[{"width":900,"height":516,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Malware-Tea.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"TeaBot &#8211; A dangerous malware targeting banks","datePublished":"2021-05-14T01:42:49+00:00","dateModified":"2021-05-14T01:42:50+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/"},"wordCount":323,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Malware-Tea.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/","url":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/","name":"TeaBot - A dangerous malware targeting banks - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Malware-Tea.jpg","datePublished":"2021-05-14T01:42:49+00:00","dateModified":"2021-05-14T01:42:50+00:00","description":"Bank data is always a desired asset by cybercriminals and this is how this threat called TeaBot arrives, which we will see and analyze today.","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Malware-Tea.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Malware-Tea.jpg","width":900,"height":516},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/teabot-a-dangerous-malware-targeting-banks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"TeaBot &#8211; A dangerous malware targeting banks"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2687","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2687"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2687\/revisions"}],"predecessor-version":[{"id":2699,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2687\/revisions\/2699"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2688"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2687"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2687"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2687"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}