New Android malware ‘Brokewell’ can steal user data and access banking apps

Jugo Mobile
By
Jugo Mobile
Jugo Mobile is a platform dedicated to high-quality content in gaming, sports, and tech. Engage with high-quality content and connect with fellow enthusiasts and experts. Explore...
4 Min Read

A warning has been issued to millions of Android users about a new, previously undocumented malware that uses fake Google Chrome updates to trick users and put their devices at risk. The Trojan malware, dubbed “Brokewell,” can siphon user data, access banking apps, spy on users, and even allow attackers to gain full remote access to Android devices.

“Brokewell represents a significant threat to the banking industry as it provides attackers with remote access to all assets available through mobile banking,” the Dutch security firm said. ThreatFabricsaidin an analysis published this week. The malware, which is equipped “with remote control and data theft capabilities,” gains access to victims’ Android devices by tricking them into installing the Brokewell Trojan on their phones.

It is disguised as an update for a new version of Google Chrome, and even uses a visual design similar to the legitimate Chrome installation message to avoid suspicion. Although with some obvious grammatical errors, a common sign of these types of scams. Instead of saying “Browser built to be yours” like the original Google message, the fake Brokewell-infested version says “An update from you is required.”

Once downloaded, Brokewell creates an overlay screen in front of any app you are using to capture login details, steal session cookies, and even type or click on the phone screen to steal funds from the compromised device.

The malware itself is “a never-before-seen family of malware with a wide range of capabilities,” ThreatFabric said. Worse yet, Brokewell appears to be in active development and receives regular updates. ThreatFabric traced the malware to a hacker named Baron Samedit Marais, who allegedly sells it along with a variety of other malicious tools through a site called Brokewell Cyber ​​Labs.

“We anticipate further evolution of this malware family, as we have observed almost daily updates to the malware,” the firm said. “Brokewell will likely be promoted on underground channels as a rental service, attracting the interest of other cybercriminals and prompting new campaigns targeting different regions.”

How to stay safe from Android malware

smartphone malware

(Image credit: Shutterstock)

Android malware is not uncommon. Earlier this month, it was discovered that hackers were injecting scripts into websites to display fake Chrome update errors to infect unsuspecting users with malware. When it comes to protecting yourself from Android malware, the first and most important thing you can do is be very careful when downloading and installing updates or new apps.

If you have one of the best Android smartphones, chances are it comes with Google Play Protect pre-installed. Make sure this app is enabled as it can scan all your existing apps and any new ones you download for malware. Likewise, for extra protection, you may also want to consider installing one of the best Android antivirus apps to run alongside it.

  • This Android malware can steal all your photos and texts without opening it: how to stay safe
  • Fake job ads on Facebook use malware to siphon credit card data and passwords
  • 26 Billion Records Exposed Online in Largest Data Breach in History: What to Do Now

Share This Article
Follow:
Jugo Mobile is a platform dedicated to high-quality content in gaming, sports, and tech. Engage with high-quality content and connect with fellow enthusiasts and experts. Explore the latest trends and innovations in our vibrant community. Join us and experience the future today!
Leave a Comment
Grow your brand and reach a larger audience. Advertise with us today and get noticed by thousands.
© 2025 Jugo Mobile. All Rights Reserved.