First Tech Credit Union has notified its members about a fraudulent app in the Android Market that attempts to phish for financial info.
Source: http://www.firsttechcu.com
UPDATE: Rogue Android Smartphone app created
We recently learned that a fraudster developed a rogue Android Smartphone app, Droid09, which tries to gain access to a consumer’s financial information. As a reminder, we don’t currently have an Android phone app. This attack did not target First Tech. Learn more about the phishing scam.
From http://www.firsttechcu.com/home/security/fraud/security_fraud.html:
12.22.09 Rogue Android Smartphone app created
We recently learned that a fraudster developed a rogue Android Smartphone app. It creates a shell of mobile banking apps that tries to gain access to a consumer’s financial information.
Droid09 launched this phishing attack from the Android Marketplace and it’s since been removed. It’s called phishing because scammers go fishing for information about you or your financial account that may be used for identity theft.
Please note that this attack didn’t target First Tech accounts. Accessing your First Tech account from your phone’s web browser is completely secure.
If you did download the Droid09 app, please remove it from your phone and take it to your mobile provider to ensure it’s completely removed.
As a reminder, we don’t currently have an app for the Android phone.
I guess this is the result of Google’s lax app review policy. I guess it was bound to happen.



2 Responses
[...] from Apple’s strict policies, but I think it might also opens the door for rogue apps like Droid09. If you are interested in creating your own app store check out YourAppShop. (It’s nothing [...]
[WORDPRESS HASHCASH] The comment’s server IP (97.74.24.112) doesn’t match the comment’s URL host IP (173.201.1.1) and so is spam.
[...] through (as far as I can tell, there’s no approval step). So, what you get is a lot of spam, malicious apps and now this latest one benign, but not [...]