Sunday, March 19, 2023
  • Advertise With Us
  • Write For Us
  • Contact Us
  • About Us
  • Editorial Calendar
Download Latest Issue - Free!
The Cyber Express
Ransomware Report
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Gamekaking Data Breach

    Gamekaking Data Breach? Leakbase Claims to Upload 19 Million Rows of Stolen Information

    Medusa Ransomware Group

    Medusa Ransomware Group Targets National Institute of Ocean Technology

    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Clop Ransomware Group Adds Hitachi Energy

    Hitachi Energy Confirms Security Incident After Clop Ransomware Adds it to Victim List

    Onex Data Exposed

    Onex Data Exposed, Linked to GoAnywhere MFT Security Incident

    Euler Finance Cyber Attack

    Euler Finance Cyber Attack Hackers Returns $165k to Victim

    Independent Living Systems Data Breach

    Independent Living Systems Data Breach Puts 4.2 Million Individuals at Risk

    Loyola University Data Breach

    Loyola University Data Breach, Hackers Claim to Have Access to Personal Student Data

    Pornhub

    Pornhub Removes Wagner Ad Recruiting Soldiers For Russian War

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Insider threat mitigation

    Behavioral Psychology, a Boon for Insider Risk Mitigation

    Safer Internet

    International Safer Internet Day: How Safe Are Our Teenagers Online?

    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    Privacy Penalty Bill

    Privacy Penalty Bill: Australian Parliament Approves Heavy Fines

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    GISEC Global 2023

    GISEC Global 2023: Knowledge Sharing, Collaboration Vital to Fend off Cyberattacks, say Experts

    Call & Contact Center Expo 2023 Las Vegas

    Call & Contact Center Expo 2023 Las Vegas

    Former BookMyShow CTO Mahesh Vandi Chalil

    Cyble Appoints Former BookMyShow CTO Mahesh Vandi Chalil as Chief Product and Technology Officer

    GISEC 2023

    GISEC 2023: Microsoft Highlights Zero Trust Approach and Mixed Reality Policing Tools

    GISEC Global 2023

    GISEC Global 2023: ‘Take the Fight to Cyber Attackers’ Urges UAE Cybersecurity Council Paper

    Cyble in Forbes List

    Cyble Recognized by Forbes as One of America’s Best Startup Employers 2023

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Cyble Among Top 50 Emerging Companies

    Cyble Among Top 50 Emerging Companies Across Governance Risk & Compliance Solutions Sector

    Call and Contact Center Expo

    The Countdown Begins: The Call and Contact Center Expo Las Vegas 2023 is Officially Here!

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • World CyberCon Middle East 2023
    • Endorsed Events
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Gamekaking Data Breach

    Gamekaking Data Breach? Leakbase Claims to Upload 19 Million Rows of Stolen Information

    Medusa Ransomware Group

    Medusa Ransomware Group Targets National Institute of Ocean Technology

    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Clop Ransomware Group Adds Hitachi Energy

    Hitachi Energy Confirms Security Incident After Clop Ransomware Adds it to Victim List

    Onex Data Exposed

    Onex Data Exposed, Linked to GoAnywhere MFT Security Incident

    Euler Finance Cyber Attack

    Euler Finance Cyber Attack Hackers Returns $165k to Victim

    Independent Living Systems Data Breach

    Independent Living Systems Data Breach Puts 4.2 Million Individuals at Risk

    Loyola University Data Breach

    Loyola University Data Breach, Hackers Claim to Have Access to Personal Student Data

    Pornhub

    Pornhub Removes Wagner Ad Recruiting Soldiers For Russian War

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Insider threat mitigation

    Behavioral Psychology, a Boon for Insider Risk Mitigation

    Safer Internet

    International Safer Internet Day: How Safe Are Our Teenagers Online?

    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    Privacy Penalty Bill

    Privacy Penalty Bill: Australian Parliament Approves Heavy Fines

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    GISEC Global 2023

    GISEC Global 2023: Knowledge Sharing, Collaboration Vital to Fend off Cyberattacks, say Experts

    Call & Contact Center Expo 2023 Las Vegas

    Call & Contact Center Expo 2023 Las Vegas

    Former BookMyShow CTO Mahesh Vandi Chalil

    Cyble Appoints Former BookMyShow CTO Mahesh Vandi Chalil as Chief Product and Technology Officer

    GISEC 2023

    GISEC 2023: Microsoft Highlights Zero Trust Approach and Mixed Reality Policing Tools

    GISEC Global 2023

    GISEC Global 2023: ‘Take the Fight to Cyber Attackers’ Urges UAE Cybersecurity Council Paper

    Cyble in Forbes List

    Cyble Recognized by Forbes as One of America’s Best Startup Employers 2023

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Cyble Among Top 50 Emerging Companies

    Cyble Among Top 50 Emerging Companies Across Governance Risk & Compliance Solutions Sector

    Call and Contact Center Expo

    The Countdown Begins: The Call and Contact Center Expo Las Vegas 2023 is Officially Here!

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • World CyberCon Middle East 2023
    • Endorsed Events
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Features

Global Banking Apps Under Attack: Researchers Find ‘InTheBox’ Web Injects

This web inject is designed to target retail banking, mobile payment services, cryptocurrency exchanges, and mobile e-commerce applications of major organizations across various countries.

Ashish Khaitan by Ashish Khaitan
February 1, 2023
in Features, Firewall Daily
0
InTheBox
611
SHARES
3.4k
VIEWS
Share on LinkedInShare on Twitter
Listen to this story

A Russian threat actor has been growing stock on a Tor-based online store with web injects that are ready to sell and work with different Android banking malware, researchers found.

They are offering these web injects at low prices and attractive discounts. Cyble Research and Intelligence Labs (CRIL) discovered an uprising threat group from Russian hacking forums, explicitly targeting banking applications.

You might also like

Gamekaking Data Breach? Leakbase Claims to Upload 19 Million Rows of Stolen Information

Medusa Ransomware Group Targets National Institute of Ocean Technology

FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

The research team has been closely monitoring the actions of a notorious threat actor/group known as “InTheBox”.  

Lurking in the shadows of a Russian language cybercrime forum, this group has expanded its reach with a sinister arsenal of web injects. Housed in their Tor-based online shop, these ready-to-use web injects can be paired with various Android banking malware and are offered at bargain prices with alluring discounts. 

What is ‘InTheBox’? 

InTheBox” is a known threat actor or group in the cybercrime community. According to the CRIL report, these groups are primarily active on a Russian language cybercrime forum and are known for offering web injects for sale through their Tor-based online shop. 

This web inject is designed to target retail banking, mobile payment services, cryptocurrency exchanges, and mobile e-commerce applications of major organizations across various countries.  

Since February 2020, the infamous group “InTheBox” has made a name for itself as a verified seller of Android mobile application web injects.  

The group runs a Tor-based online shop that offers a seamless shopping experience for those seeking to purchase web injects. With enticing discounts and an effortless purchasing process, it’s no wonder that “InTheBox” has become popular among those looking to inflict harm on the digital world. 

While earlier gaining access to the tor website was by simply registering for free, now “InTheBox” has upped the ante, requiring a one-time fee for entry. Despite the added barrier, it’s clear that “InTheBox” remains a dangerous force to be reckoned with in the world of cybercrime. 

How Android web injection work? 

 Android web inject is a custom-made module crafted to harvest sensitive information and is the perfect disguise for banking malware.  Victims are lured into a false sense of security with a deceptive overlay interface mimicking a legitimate mobile application.

The web injects acts like a sly thief, silently slipping into the shadows and snatching away valuable credentials and sensitive data.  This attack vector is reminiscent of the age-old Man-in-the-Browser (MITB) attack, a constant threat to those who roam the digital landscape.” 

“InTheBox” has taken the cybercrime world by storm, shaking up the market with their newly reduced prices on individual web injects. What was once a costly investment of $50 can now be had for a mere $30. And for those looking for a truly personalized touch, “InTheBox” offers custom web injection development, tailoring their deadly wares to fit the specific needs of any banking malware bot. 

Starting with a targeted assault on organizations in the US, Australia, and South America, “InTheBox” has broadened its scope, now casting its net over 44 countries. Their relentless pursuit of power and profit knows no bounds, making them a force to be reckoned with in the digital world. 

The web injection, disguised as a benign overlay interface, coaxes unsuspecting users into entering their precious mobile banking credentials, such as user ID, password, and mobile number. However, this is just the tip of the iceberg, as the real damage is yet to come. 

A second overlay interface pops up, tricking the user into handing over their credit card information, including the number, expiry date, and CVV code – information that may not even be necessary for the legitimate app.  

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: InTheBox
Previous Post

Why Singapore Has the Best Cybersecurity in The World

Next Post

US Healthcare Sector Under Attack, Killnet Adds 50 Hospitals to Target List

Ashish Khaitan

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

Related Posts

Gamekaking Data Breach
Dark Web News

Gamekaking Data Breach? Leakbase Claims to Upload 19 Million Rows of Stolen Information

by Ashish Khaitan
March 18, 2023
Medusa Ransomware Group
Data Breach News

Medusa Ransomware Group Targets National Institute of Ocean Technology

by Ashish Khaitan
March 18, 2023
BreachForums
Compliance

FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

by Chandu Gopalakrishnan
March 18, 2023
Clop Ransomware Group Adds Hitachi Energy
Data Breach News

Hitachi Energy Confirms Security Incident After Clop Ransomware Adds it to Victim List

by Vishwa Pandagle
March 18, 2023
Onex Data Exposed
Data Breach News

Onex Data Exposed, Linked to GoAnywhere MFT Security Incident

by Vishwa Pandagle
March 17, 2023
Next Post
Killnet

US Healthcare Sector Under Attack, Killnet Adds 50 Hospitals to Target List

Latest Issue is Out. Subscribe Now

Women in Cybersecurity

Download Now

CRIL


Follow Us On Google News

Never miss an update. Subscribe!

* indicates required

Top 10 Cybersecurity Jobs

Categories

About The Cyber Express

The Cyber Express

Cyber Security News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

Follow The Cyber Express

Contact

For editorial queries: [email protected]

For marketing, PR & media partnerships: [email protected]

For media kit and digitals sales: [email protected]

For Sponsorship/Event Partnership: [email protected]

For Conferences related information: [email protected]

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

Tel: (678) 578-8838

Events: +1 (678) 578-4140

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Tel: (678) 578-8838

Events: +1 (678) 578-4140

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Firewall Daily
  • Business News
  • Cyber Essentials
  • Features
  • Cyber Security Magazine
  • Events
    • World CyberCon Middle East 2023
    •  Cyber Security Webinar

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.