Google removes fake 2FA app stealing banking credentials

Jan

Who's the Boss?
Staff member
Joined
May 24, 2010
Messages
14,810
Reaction score
13,463
Location
The Rabbit Hole
Google nukes two-factor authenticator virus app

Google has removed a fraudulent two-factor authentication app from its Play Store after it was discovered to be stealing users' financial information on Android smartphones.

2FA Authenticator — as the app was named — was identified to be a trojan-dropper as it is leveraged by cybercriminals to install malware secretly.
 
The 2FA Authenticator application spent 15 days on the Play store before Google removed it.
Why didn't Google's Play Store app scanning detect and prevent this malware from entering the wild?

There are strange things afoot at Google/Alphabet, take YouTube as just one example of a platform where AI has gone horribly wrong and there is seemingly no incentive to fix the problems (it's almost as if the AI cannot be fixed).
 
Last edited:
Why didn't Google's Play Store app scanning detect and prevent this malware from entering the wild?

There are strange things afoot at Google/Alphabet, take YouTube as just one example of a platform where AI has gone horribly wrong and there is no seemingly incentive to fix the problems (it's almost as if the AI cannot be fixed).
 
No thanks syncing your 2FA with the cloud defeats its purpose.
That's optional.
Useful for those who often change devices. The cloud save is encrypted be of course.

It beats Google Authenticator in password saves (also optional, btw), and cooler integration with Msft's own online services like Azure, Microsoft 365, etc.
 
Top
Sign up to the MyBroadband newsletter
X