• Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Trending

Trump’s Defiance of TikTok Ban Prompted Immunity Promises to 10 Tech Companies

August 16, 2025

3 Questions That Can Instantly Defuse Any Argument, By A Psychologist

August 16, 2025

The ‘Thoughtless’ Meeting Habit Your Team Hates

August 16, 2025
Facebook Twitter Instagram
  • Newsletter
  • Submit Articles
  • Privacy
  • Advertise
  • Contact
Facebook Twitter Instagram
UptownBudget
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Subscribe for Alerts
UptownBudget
Home » Google’s Play Store Warning—Do Not Update This Setting
Innovation

Google’s Play Store Warning—Do Not Update This Setting

adminBy adminMarch 31, 20250 ViewsNo Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email

Beware — there is a new threat to worry any Android user with popular banking and shopping apps on their phone. A nasty trojan has been discovered attacking more than 750 legitimate banking and shopping apps, presenting a fake login screen over the real app, stealing your credentials as soon as they’re entered.

This new discovery by Cyble comes just days after Google warned Android users that sideloaded apps from third-party stores and direct installs deliver 50–times as much malware as apps from Play Store. Ironically, although this new threat is sideloaded, its dropper is “disguised as Google Play Services,” giving it seeming legitimacy. The attack requires a Play settings update that Google has repeatedly warned can be dangerous.

Cyble has dubbed this TsarBot given the likely Russian origins of its developers, and says it can “remotely control the screen, executing fraud by simulating user actions such as swiping, tapping, and entering credentials while hiding malicious activities using a black overlay screen. It captures device lock credentials using a fake lock screen to gain full control, [and it can]

send stolen data, and dynamically execute on-device fraud.”

TsarBot isn’t limited to overlay attacks given its remote control capabilities. One of which relates to two-factor authentication (2FA), a necessity for the apps it attacks, through “lock-grabbing techniques, keylogging, and intercepting SMS messages.”

An attack starts with an install from a dangerous phishing website. Cyble observed a fake version of a token trading platform, but it could be any website and attackers will move on to keep ahead of discovery. “The phishing site delivers a dropper application that stores the TsarBot APK file, implant.apk, in the “res/raw” folder. The dropper utilizes a session-based package installer to deploy the TsarBot malware on the device.”

After install, the Play Services trick comes into play — so to speak. “TsarBot conceals itself as the Google Play Service app and does not display a launcher icon. Upon installation, it presents a fake Google Play Service update page, prompting the user to enable Accessibility services.” Do not click OK to agree this app update.

“By abusing Accessibility services and WebSocket communication,” Cyble warns, “TsarBot underscores the persistent threat posed by banking malware. Users should exercise caution when installing apps, avoid untrusted sources, and remain vigilant against phishing sites distributing such threats.”

Staying safe is very straightforward. Do not install apps from outside Play Store or other official Android stores. Ensure Play Protect is enabled at all times, and do not be lured into disabling or pausing this for an install unless you’re 100% sure it’s safe and know the source beyond doubt. And don’t enable Accessibility Services” unless an app categorically requires device controls to function. It opens up significant risks.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

3 Questions That Can Instantly Defuse Any Argument, By A Psychologist

Innovation August 16, 2025

4 Dismissive Phrases To Avoid In Your Relationship, By A Psychologist

Innovation August 15, 2025

Bandai Spirits Is Doing A Metal Gear REX Chogokin Toy

Innovation August 14, 2025

Wyze’s Duo Cam Pan Doubles Up To Kill Blind Spots

Innovation August 13, 2025

How The Dutch Got Their Cycle Paths: In Song

Innovation August 12, 2025

Wikipedia May Have To Impose Identity Verification On Readers

Innovation August 11, 2025
Add A Comment

Leave A Reply Cancel Reply

Editors Picks

Trump’s Defiance of TikTok Ban Prompted Immunity Promises to 10 Tech Companies

August 16, 2025

3 Questions That Can Instantly Defuse Any Argument, By A Psychologist

August 16, 2025

The ‘Thoughtless’ Meeting Habit Your Team Hates

August 16, 2025

Kim Perell Shares The Mistakes That Made Her a Millionaire

August 15, 2025

Inside Dylan Field’s Big IPO—and His Even Bigger Plans for Figma

August 15, 2025

Latest Posts

Walmart Employee’s ‘Magic’ Side Hustle Surpasses $1 Million

August 15, 2025

Inclusion Isn’t Just a Checkbox Anymore — It’s What Investors Are Looking For

August 15, 2025

How to Build a Startup That Actually Attracts a VC

August 14, 2025

What Does Palantir Actually Do?

August 14, 2025

Bandai Spirits Is Doing A Metal Gear REX Chogokin Toy

August 14, 2025
Advertisement
Demo

UptownBudget is your one-stop website for the latest news and updates about how to start a business, follow us now to get the news that matters to you.

Facebook Twitter Instagram Pinterest YouTube
Sections
  • Growing a Business
  • Innovation
  • Leadership
  • Money & Finance
  • Starting a Business
Trending Topics
  • Branding
  • Business Ideas
  • Business Models
  • Business Plans
  • Fundraising

Subscribe to Updates

Get the latest business and startup news and updates directly to your inbox.

© 2025 UptownBudget. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.