Skip to content

Malware

Ginp

Ginp is a mobile banking software targeting Android devices that was discovered by Kaspersky.

Ginp is a Android malware family.

Background

First identified by Kaspersky, Ginp is an Android banking malware that uses overlay attacks to capture both login credentials and credit card data, with the default SMS app being one of the applications it overlays. The family stands out for the way its operators kept it hidden for years while continuously rolling out new versions. ThreatFabric attributes the following capabilities to Ginp:

Overlaying: Dynamic (local overlays obtained from the C2) SMS harvesting: SMS listing SMS harvesting: SMS forwarding Contact list collection Application listing Overlaying: Targets list update SMS: Sending Calls: Call forwarding C2 Resilience: Auxiliary C2 list Self-protection: Hiding the App icon Self-protection: Preventing removal Self-protection: Emulation-detection.


Source: Malpedia (Fraunhofer FKIE).