started · updated
Cybercriminals exploit mobile accessibility permissions to steal bank funds
Police and various Vietnamese banks are warning against a growing cybercrime tactic where criminals seize control of mobile phones to steal funds. Scammers often impersonate police officers, tax officials, or bank staff, tricking victims into installing malicious applications via links for purposes such as “information authentication” or “tax refunds.”
These malicious apps, often distributed as APK files on Android devices, exploit Accessibility permissions to gain deep control over the device. Once granted, attackers can view the screen, capture passwords, PINs, and OTPs, and even perform unauthorized transactions. Criminals typically wait until late at night or when accounts have high balances to transfer money.
In one reported case in Ha Dong, Hanoi, a victim lost 1.5 billion VND after installing a fake public service application. Major banks, including Vietcombank, VPBank, MB, ACB, TPBank, SHB, and LPBank, have issued warnings advising Android users to immediately disable Accessibility permissions for any unknown or suspicious applications.
Entities
ACB · MB Bank · TPBank · VPBank · Vietcombank