There is a new Android banking malware which evolves to steal crypto users credentials as well. And it used to target Brazilian banks, but now it has grown and evolved and expanded it targets to include other banking system as well.
Most of the targeted apps were for Brazilian banks, but in recently updated versions, Kaspersky said Ghimob also expanded its capabilities to start targeting banks in Germany (five apps), Portugal (three apps), Peru (two apps), Paraguay (two apps), Angola and Mozambique (one app per country).
Furthermore, Ghimob also added an update to target cryptocurrency exchange apps in attempts to gain access to cryptocurrency accounts, with Ghimob following a general trend in the Android malware scene that has slowly shifted to target cryptocurrency owners.
After any phishing attempt was successful, all collected credentials were sent back to the Ghimob gang, which would then access a victim's account and initiate illegal transactions.
So do not download anything that mimicked the following.
- Google Defender
- Google Docs
- WhatsApp Update
- Flash Update
https://www.zdnet.com/article/new-ghimob-malware-can-spy-on-153-android-mobile-applications/In did not mentioned which crypto apps in it, but according to this
report, it's 13 crypto apps from different countries.