We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Trojan:AndroidOS/Banker.M
Aliases: No associated aliases
Summary
This threat is a trojan spyware that masquerades as legitimate mobile banking applications of financial organizations. Attackers typically use phishing to trick users into installing the malicious mobile banking applications. The app spies on user activities, collects personal information such as the user’s contacts, SMS messages, call logs, and device information, and uploads this data to the attacker’s command-and-control (C2) server.
For more information and guidance from Microsoft, read the following:
To help reduce the impact of this threat, you can:
- Immediately uninstall the fake application
- Install antivirus software on your mobile device
Microsoft Defender Antivirus automatically removes threats as they are detected. If you have cloud-delivered protection, your device gets the latest defenses against new and unknown threats. If you don't have this feature enabled, update your antimalware definitions and run a full scan to remove this threat.
You can also visit our advanced troubleshooting page or search the Microsoft community for more help.