New 'Brokewell' Android malware can steal user data and access banking apps

Android logo on phone next to Malware sign
(Image credit: Getty Images)

A warning has been issued to millions of Android users regarding new previously undocumented malware that uses fake Google Chrome updates to trick users into putting their devices at risk. The Trojan malware, dubbed "Brokewell," can siphon user data, access banking apps, spy on users, and even allow attackers to gain full remote access to Android devices.

"Brokewell poses a significant threat to the banking industry, providing attackers with remote access to all assets available through mobile banking," Dutch security firm ThreatFabric said in an analysis published this week. The malware, which is equipped "with both data-stealing and remote-control capabilities," gains access to victims' Android devices by tricking them into installing the Brokewell Trojan on their phones. 

It's disguised as an update for a new version of Google Chrome, even using a similar visual design as a legitimate Chrome installation prompt to avoid suspicion.  Albeit with some obvious grammatical errors — a common tell for these kinds of scams. Instead of saying "The browser built to be yours" like on the original Google prompt, the Brokewell-infested fake version reads "An update is required yours."

Once downloaded, Brokewell creates an overlay screen in front of whatever apps you're using to capture login details, steal session cookies, and even type or click on the phone's screen to steal funds from the compromised device.

The malware itself is “a previously unseen malware family with a wide range of capabilities,” ThreatFabric said. Worse still, Brokewell appears to be in active development and receives regular updates. ThreatFabric traced the malware back to a hacker named Baron Samedit Marais, who is reportedly selling it along with a range of other malicious tools through a site called Brokewell Cyber Labs.

"We anticipate further evolution of this malware family, as we've already observed almost daily updates to the malware," the firm said. "Brokewell will likely be promoted on underground channels as a rental service, attracting the interest of other cybercriminals and sparking new campaigns targeting different regions."

How to stay safe from Android malware

smartphone malware

(Image credit: Shutterstock)

 Android malware is far from uncommon. Just earlier this month, hackers were found to be injecting scripts into websites to display fake Chrome update errors to infect unsuspecting users with malware. When it comes to protecting yourself from Android malware, the first and most important thing you can do is to be extra careful when downloading and installing any updates or new apps. 

If you have one of the best Android smartphones, odds are it'll come with Google Play Protect pre-installed. Be sure to make sure that this app is enabled, as it can scan all of your existing apps and any new ones you download for malware. Likewise, for additional protection, you may also want to consider installing one of the best Android antivirus apps to run alongside it.

In an email to Tom's Guide, a Google spokesperson provided further insight on how Google Play Protect can help keep you safe from malicious apps, saying:

"Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play."

More from Tom's Guide

TOPICS
Alyse Stanley
News Editor

Alyse Stanley is a news editor at Tom’s Guide overseeing weekend coverage and writing about the latest in tech, gaming, and entertainment.Prior to joining Tom’s Guide, Alyse worked as an editor for the Washington Post’s sunsetted video game section, Launcher. She previously led Gizmodo’s weekend news desk and has written game reviews and features for outlets like Polygon, Unwinnable, and Rock, Paper, Shotgun. She’s a big fan of horror movies, cartoons, and roller skating.

Read more
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
and image of the Google Chrome logo on a laptop
Google Chrome at risk from shape-shifting browser extensions — how to stay safe
and image of the Google Chrome logo on a laptop
Billions of Chrome users at risk from new browser-hijacking Syncjacking attack — how to stay safe
Latest in Malware & Adware
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
Latest in News
Sonos logo on a smart speaker
Sonos halts work on rumored super steaming device — what's next?
NYTimes Connections
NYT Connections today hints and answers — Thursday, March 13 (#641)
HomePod with display concept render
Apple HomePod with display now rumored for late 2025 launch
The Apple Watch Series 10 on display at the device's launch in September 2024
Apple Watch sales plummet 19% as smartwatch market declines for first time
Google's Project Astra working on prototype smartglasses in an advertisement
Google just acquired this eye tracking company — hinting at the return of Google glasses
iPhone 17 Air render
iPhone 17 Air could be just 5.5mm thick — but 9.5mm when you throw in the camera bump