What Does The Revive Banking Trojan Do On Your Android Device?

Revive is the name of a new banking trojan malicious application that is used to target customers of Spanish banking institutions. The malware is used for account theft and stealing login credentials.

Revive is usually distributed under the guise of a multi-factor authentication application released from the bank in question. Of course, the app has nothing to do with the bank and is made by the criminals running the Revive trojan.

The malicious app shows a fake login page, tailored to mimic the bank's legitimate login portal. Entering user account information in this form simply hands your login info to the malware operator. This allows for practically complete account takeover.

Revive has further malicious capabilities, including keypress logging and SMS interception. With the permissions it asks for upon installation, the trojan can also hijack SMS messages containing one-time use passwords and multi-factor authentication strings sent by the system of the legitimate bank.

Similar strains of Android malware that target mobile devices and have banking trojan capabilities include the Coper, Hydra and Exobot Compact.

June 28, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.