src='https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=ca-pub-2513966551258002'/> Rightways: malicious applications Infolinks.com, 2618740 , RESELLER

Pages

Share This

Deepseek https://www.deepseek.com/./深度求索 DeepSeek | 深度求索 https://askaichat.app/chat
Showing posts with label malicious applications. Show all posts
Showing posts with label malicious applications. Show all posts

Monday, August 10, 2026

Don’t install apps under pressure, ‘I watched them take control of my phone remotely’

 

Compromised: Scammers are finding more sophisticated ways to bypass safeguards, such as malicious apps disguised as legitimate services. — Pic from magnific.com

PETALING JAYA: As smartphones become central to banking and daily life, scammers are finding increasingly sophisticated ways to seize control of the devices and the accounts within.

Universiti Sains Malaysia Cybersecurity Research Centre director Prof Dr Selvakumar Manickam said criminals were now turning to remote-access tools and malicious applications to bypass conventional scam safeguards.

He said victims could be persuaded to install apps such as AnyDesk or TeamViewer or malicious Android Package Kit (APK) files disguised as legitimate banking, delivery or other services.

Once installed and given permissions such as accessibility access, scammers could potentially view and operate the victim’s phone, including banking applications.

“An unsolicited caller asking the victim to download an app to ‘resolve’ an issue, a request to enable accessibility, SMS or ‘install unknown apps’ permissions, or being asked to remain on a call while installing something, should raise alarm bells,” he said when contacted.

Unexpected battery drain or unusual phone behaviour after installing an application, particularly one downloaded outside authorised sources, are also warning signs.

Selvakumar said scammers were increasingly exploiting psychology rather than simply trying to defeat technical security measures.

“They may create a sense of urgency by claiming a bank account has been frozen, a police matter needs to be resolved or an unpaid bill requires immediate action.

“Generative AI is also making scams more convincing with criminals able to produce polished phishing messages in local languages and clone voices to impersonate family members, bank officers or government officials,” he said.

Beyond screen control, malware can quietly intercept SMS messages and push notifications, including one-time passwords and two-factor authentication codes, before forwarding them to scammers.

Some newer malware could also identify a victim’s SIM card and mobile carrier before subscribing them to premium services through mobile billing systems.

“Fake cellular base stations have also been detected locally, allowing criminals to send fraudulent SMS messages while bypassing some telco-level filtering,” he added.

Selvakumar said the affected phone should subsequently be reset after important data has been backed up or checked by a trusted technician.

“The lesson is simple – never allow urgency or fear to override basic security precautions,” he said.

Cybersecurity expert Fong Choong Fook said social engineering remained one of the biggest threats despite growing public awareness.

“Don’t install any unknown or suspicious software. Have good practices such as not clicking on links from strangers or SMS,” he said.

Fong added that scammers impersonating bank employees, law enforcement officers and government officials could now use AI-generated voice and video to make their identities appear more convincing.

“Users should avoid public WiFi where possible as compromised networks could expose devices to additional risks.”

‘I watched them take control of my phone remotely’


PETALING JAYA: A routine phone call can quickly turn into a financial nightmare when unsuspecting victims lose control of their smartphones to scammers.

Confidential information and other personal details will then be manipulated by these fraudsters, causing financial and emotional distress to the victims.

For a Shah Alam resident who wished to be known only as Lim, the scam started with a phone call from a “bank officer”, warning him about suspicious transactions.

The caller instructed him to download an application, purportedly to verify his identity and secure his account.

Thinking he was following a security procedure, Lim installed the application and granted the requested authorisation.

“After installing it, it seemed that someone had taken control of my phone.

“I could see apps opening by themselves, but I could not control what was happening,” said the 42-year-old.

Within minutes, the scammers had gained access to his banking application and made several transactions.

Lim claimed that he lost about RM7,800 from his account before he managed to disconnect the phone from the Internet and contacted the bank.

“I always thought scams happened because people clicked suspicious links.

“I never expected that scammers could take over my phone while I was still holding it.

“By the time you realise it is the work of a scammer, it is too late, as you have probably already suffered financial losses,” he said.

Another victim, who wished to be known as Tan, 56, from Ipoh, said she was contacted through WhatsApp on July 1.

The caller informed her that she had won a RM3,000 prize and was offered a choice between shopping vouchers or cash credited to her e-wallet.

Tan said she opted for a cash reward, and the call was subsequently transferred to a “manager”, who sounded like a foreigner.

“I just followed his instruction to claim the reward.

“He then took control of my phone screen and kept directing me from one site to another without giving me time to think,” she said.

Tan said she then contacted the platform’s customer service through the app, activated the kill switch and lodged a police report within an hour.

She also said the official complaint submitted through the app, together with screenshots and supporting documents, later disappeared from her phone.

Tan claimed that RM4,500 was charged to her pay-later account while another RM6,000 was withdrawn through the platform’s loan facility, bringing her total losses to RM10,500.

“The RM6,000 purported loan was converted into a 24-month repayment plan, requiring a monthly instalment of over RM300.

“The sum of RM4,500 was transferred to an entity listed as ‘Lucky Boy Trading’, although I had not purchased any items,” she said.

A victim from Subang, who identified himself as Ravi, 35, said scammers posing as delivery company employees convinced him to install an application to reschedule a parcel.

After granting the application access to his phone, he noticed that messages and notifications were appearing and disappearing without his involvement.

“I thought I was only following instructions to receive a parcel. I never expected them to be able to take control of my phone.”