A Brazil-based threat group that recently has been expanding its operations worldwide has deployed a new banking Trojan that is actively targeting Android users in multiple Latin American and European countries and could soon hit US users as well.
Researchers at Kaspersky recently discovered the so-called “Ghimob” remote access Trojan (RAT) while investigating another malware campaign. In a report this week, the security vendor described the malware as arriving on mobile devices via email purporting to be about some kind of debt.
Recipients who fall for the scam and click on an embedded link in the email end up downloading the RAT on their devices. Once installed, Ghimob is capable of a variety of malicious actions that start with sending a message about successful infection to an attacker-controlled server.
The initial…