An Android Malware Can Steal Money From PayPal Account
Aadhya Khatri
ESET discovered a malware that can transfer money from users' PayPal accounts even if they have the 2 factor authentication on.
- How 30 Lines Of Code Destroy A 27-Ton Generator
- If You Want To Be Safe, Please Stay Away From These Fake Coronavirus Websites
- The Most 'Dangerous' Movie In The World - 'Joker'
ESET, a company that provides IT security solutions, has discovered a malware that can transfer money from Paypal without user’s permission even if their 2FA is on. This malicious software hides inside a battery optimization app.
The video below shows how this process works:
The good news here is this app is unavailable on the Play Store but is distributed through a third-party app store, which means not many people have fallen under the threat of the malware.
However, you should not put down your guards just yet. This app contains a system that can initiate money transfer without user’s notice, and when they do, it is often too late.
The malware is able to do this by asking for permission to access Android Accessibility. It is then able to automate OS interactions and screen taps.
Once it gains the access, the system does not transfer any money right away. Both the trojan and the app remain silent until the user logs into the PayPal app. It waits until the user does this on his own or sends a fake notification to trick users into opening the app.
Its next step is to wait for the user to type his 2FA code and then it starts taking action.
ESET found out about this malware through the device from one of its customers because the malicious software takes advantage of the Android Accessibility to imitate screen taps.
A new PayPal transfer is initiated; next, the PayPal account of the receiver and a sum of money are entered. Finally, the Trojan approves the transfer.
According to Lukas Stefanko, ESET malware analyst, this whole malicious process takes under 5 seconds. If the users do not suspect and take action in time, there is no way they can prevent being stolen from. The default number the Trojan takes is 1000 units in Paypal account currency. In the case of ESET, the sum is €1,000.
The malware is programmed to steal every time the user opens their PayPal app. However, if the user’s account does not have any money left or is empty, it cannot perform its wicked trick.
By abusing the Accessibility, the Trojan can also obtain user’s contact list, steal card details and Google account as well as mobile banking app’s credentials.
PayPal has been notified about this matter, and victims of this app can ask for transaction reversal.
Featured Stories
How To - Mar 04, 2026
Getting Started with AI: A Newbie's Simple Guide
ICT News - Mar 03, 2026
Budget Entry-Level PCs Under $500 to Vanish by 2028 Due to Memory Price Surge
ICT News - Mar 02, 2026
IDC Report Predicts Surging Smartphone Prices Due to Global RAM Shortage
ICT News - Mar 01, 2026
Samsung Links Galaxy S26 Price Hikes to AI Memory Supply Issues
ICT News - Feb 28, 2026
Anthropic Blacklisted by US Department of War: Trump Orders Federal Ban Over AI...
ICT News - Feb 26, 2026
AI Models Frequently Resort to Nuclear Escalation in Simulated Crises, Study...
ICT News - Feb 23, 2026
It's Over for Xbox: Asha Sharma Takes Over to Ruin Microsoft Gaming with AI
ICT News - Feb 22, 2026
Which AI Model Excels at Which Task in 2026: A Comprehensive Guide
ICT News - Feb 21, 2026
AI Coding Agent Causes Major AWS Outage at Amazon
ICT News - Feb 20, 2026
Tech Leaders Question AI Agents' Value: Human Labor Remains More Affordable
Read More
How To- Mar 04, 2026
Getting Started with AI: A Newbie's Simple Guide
Are you curious about artificial intelligence but not sure where to begin? You are not alone.
ICT News- Mar 02, 2026
IDC Report Predicts Surging Smartphone Prices Due to Global RAM Shortage
This development underscores the broader ripple effects of the AI boom on everyday technology, highlighting the interconnected nature of global semiconductor supply chains.
ICT News- Mar 03, 2026
Budget Entry-Level PCs Under $500 to Vanish by 2028 Due to Memory Price Surge
The era of the sub-$500 PC appears to be ending.