The OverlayPhantom Android banking trojan is actively targeting over 180 financial and cryptocurrency applications across ten countries by impersonating trusted platforms like TikTok and government identity apps. This malware leverages a sophisticated two-stage infection process to abuse Android’s Accessibility Service and MediaProjection API, enabling attackers to stream screens in real-time and execute over 30 remote commands. Security professionals must prioritize monitoring for malicious Accessibility Service requests and the use of counterfeit HTML overlays that harvest credentials.
Read the full article at Cyber Security News
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





