Skip to content
Saturday, June 20, 2026
MALIKA KAROUM CHATGPT

MALIKA KAROUM CHATGPT

– THE NEW WEB 3.0 FUTURE –

  • Definitions of Metaverse
  • Malika Karoum: Artificial Intelligence
  • Malika Karoum: Definition
  • Malika Karoum Metaverse
    • Metaverse Digital Virtual Environment
    • A FUTURE METAVERSE
    • METAVERSE -THE NEW FUTURE-
    • Art – The Next Generation
    • The New Web 3.0
    • Metaverse project
    • What are Non Fungible Tokens (NFT-tokens)?
    • What are NFTs?
  • Malika Karoum Media

Warning: Android Malware Can Empty Your PayPal Account

Malika Karoum Online News
January 6, 2019January 6, 2019Malika Karoum Dubai
android-paypal-malware

It’s no surprise that the end of 2018 had its fair share of cybersecurity stories. As ever, there’s so much going on in the world of online privacy, data protection, and cybersecurity that keeping up is tricky.

Our monthly security digest will help you keep tabs on the most important security and privacy news every month. Here’s what happened in December 2018!

1. Android Malware Steals From PayPal Accounts

Midway through December security experts at ESET announced the discovery of a new Android malware that steals money directly from PayPal accounts—even with two-factor authentication turned on.

ESET security researchers released the above video detailing how the malware works.

What you see in that video is the researcher logging into a test account with their 2FA code. As soon as the researcher enters their 2FA code, the account automates a payment to a pre-configured account. In this case, the payment failed because it was a test account without enough funds to process the payment.

The malware poses as a battery optimization app, called Optimization Android. Tens of other battery optimization apps use the same logo, as well as featuring similarly unobtrusive names.

Once installed, Optimize Android requests the user to turn on a malicious access service disguised as “Enable statistics.” If the user enables the service, the malicious app checks the target system for the official PayPal app and if found, the malware triggers a PayPal notification alert prompting the victim to open the app.

“Once the user opens the PayPal app and logs in, the malicious accessibility service (if previously enabled by the user) steps in and mimics the user’s clicks to send money to the attacker’s PayPal address.” The ESET research blog elaborates on the 2FA evasion, too.

“Because the malware does not rely on stealing PayPal login credentials and instead waits for users to log into the official PayPal app themselves, it also bypasses PayPal’s two-factor authentication (2FA). Users with 2FA enabled simply complete one extra step as part of logging in,—as they normally would—but end up being just as vulnerable to this Trojan’s attack as those not using 2FA.”

2. Chinese Military Hackers Breach Private EU Diplomat Communications

US security outfit Area 1 detailed how a People’s Liberation Army cyber campaign has had access to private European Union communications for several years.

“In late November 2018, Area 1 Security discovered that this campaign, via phishing, successfully gained access into the computer network of the Ministry of Foreign Affairs of Cyprus, a communications network used by the European Union to facilitate cooperation on foreign policy matters,” Area 1 explained in a blog post.

“This network, known as COREU, operates between the 28 EU countries, the Council of the European Union, the European External Action Service, and the European Commission. It is a crucial instrument in the EU system of foreign policymaking.”

The hack itself appears to have been very basic. Hackers stole credentials from network administrators and other senior staffers. They used the credentials to gain high-level access to the network where they installed the PlugX malware, creating a persistent backdoor to steal information from.

After exploring the network and moving from machine to machine, the hackers found the remote file server storing all diplomatic cables from the COREU network.

The New York Times elaborates on the content of the cables, including EU worries regarding President Trump, as well as European-wide concerns regarding Russia, China, and Iran.

3. Save the Children Charity Hit by $ 1m Scam

FBI business email compromises in numbers

The US wing of the British charity, Save the Children, was scammed out of $ 1 million through a Business Email Compromise (BEC) attack.

A hacker compromised an employee email account and sent several fake invoices to other employees. The hacker pretended that several payments were required for a solar panel system for a health center in Pakistan.

By the time Save the Children’s security team realized what was going on, the money had been deposited in a Japanese bank account. However, thanks to their insurance policy, Save the Children recovered all but $ 112,000.

Unfortunately, Save the Children are far from alone in losing money through a Business Email Compromise.

The FBI estimates that businesses lost over $ 12 billion between October 2013 and May 2018. Charities make a ripe target, too, with many hackers assuming that the non-profits will have basic or lax security practices.

The UK government found that 73 percent of U.K.-based charities with incomes larger than £5 million had been targeted within the past 12 months. Finally, security researchers at Agari uncovered the makings of a massive BEC scam that used commercial lead generation services to identify 50,000 executives to target.

Need some email security pointers? The free MakeUseOf email security course is about to get up and running. Sign up right here!

4. Amazon Customers Suffer Pre-Christmas Phishing Campaign

amazon scam email via edgewave

Christmas is a difficult time for consumers. A lot is going on. Cybercriminals sought to exploit the confusion and stress that many people feel in the build-up by launching a massive malicious spam campaign centered around Amazon Order Confirmation emails.

Researchers for EdgeWave discovered the campaign and quickly realized that the end-goal was to trick unsuspecting Amazon customers into downloading the dangerous Emotet banking Trojan.

Victims receive a standardized Amazon Order Confirmation form, containing an order number, payment summary, and an estimated delivery date. These are all fake, but the spammers rely on the fact many people order multiple packages from the shopping giant and won’t pay attention.

The emails, however, have one difference. They do not display the items that are being shipped. Instead, the scammers direct the victim to hit the Order Details button. The Order Details button downloads a malicious Word document named order_details.doc.

You can see the differences in the image above. Also note the misaligned Amazon Recommendation and Amazon Account links in the email.

When the victim opens the document, Word shows the user a Security Warning, advising that “some active content has been disabled.” If the user clicks through this warning, a macro triggers that executes a PowerShell command. The command downloads and installs the Emotet Trojan.

If you think you have downloaded malware, check out the MakeUseOf malware removal guide for tips on how to start saving your system.

5. US Indicts Chinese Hackers

The US has indicted two Chinese hackers with strong links to the Chinese state-backed hacking group, APT10.

The Department of Justice alleges that Zhang Shilong and Zhu Hua have stolen “hundreds of gigabytes” of private data from more than 45 government organizations and other important US-based businesses.

“From at least in or about 2006 up to and including in or about 2018, members of the APT10 group, including Zhu and Zhang, conducted extensive campaigns of intrusions into computer systems around the world,” according to the DoJ release. “The APT10 Group used some of the same online facilities to initiate, facilitate and execute its campaigns during the conspiracy.”

The pair are well known to other Western governments, too. Another series of attacks dating back to 2014 puts the pair hacking into the networks of service providers in 12 different countries.

The day after the Department of Justice announced the indictments, officials in Australia, Canada, Japan, New Zealand, and the U.K. published official statements formally blaming China for state-backed hacking of government agencies and businesses in the respective countries.

“These actions by Chinese actors to target intellectual property and sensitive business information present a very real threat to the economic competitiveness of companies in the United States and around the globe,” said a joint statement released by U.S. Secretary of State, Michael Pompeo, and Secretary of Homeland Security, Kirstjen Nielsen.

“We will continue to hold malicious actors accountable for their behavior, and today the United States is taking several actions to demonstrate our resolve. We strongly urge China to abide by its commitment to act responsibly in cyberspace and reiterate that the United States will take appropriate measures to defend our interests.”

December Security Roundup

Those are five of the top security stories from December 2018. But a lot more happened; we just don’t have space to list it all in detail. Here are five more interesting security stories that popped up last month:

  • The extremely destructive Iranian-linked Shamoon malware reappeared in Saudi Arabia and the UAE.
  • The Australian government implemented its ridiculous encryption backdoor legislation.
  • ESET releases research detailing 21 new malware strains [PDF] for Linux operating systems.
  • Cybercriminals post dank memes on Twitter to issue commands to active malware.
  • NASA discloses a data breach that took place in October 2018; final details of the affected still unknown.

Whew, what an end to the year in security. The world of cybersecurity is constantly evolving. Keeping track of everything is a full-time job. That’s why we round up the most important and most interesting bits of news for you every month.

Check back at the start of February for everything that happened in the first month of 2019.

Still on holiday? Take some time a read about the five biggest cybersecurity threats coming your way in 2019.

Read the full article: Warning: Android Malware Can Empty Your PayPal Account

MakeUseOf

Tagged AccountAndroidEmptyMalwarePayPalWarning

Post navigation

How to Make More Money With Google Rewards
Android TV vs. Google Chromecast: Which Is Better?

Related Posts

Forgot Your iPhone Backup Password? Here’s What You Can Do

April 10, 2019April 10, 2019Malika Karoum Dubai

6 Types of Google Search Results You Shouldn’t Trust Blindly

September 4, 2019September 4, 2019Malika Karoum Dubai

Jabra’s Elite Active 75t and Elite 45h Arrive at CES 2020

January 8, 2020January 8, 2020Malika Karoum Dubai

RSS Malika Karoum Global News

  • Are the World Cup hydration breaks an excuse to run more commercials? June 20, 2026
    Some critics see the hydration breaks as another cash grab in a tournament already facing backlash for its sky-high ticket prices.
    Touria Izri
  • Lytton, B.C., under evacuation alert as wildfire burns nearby June 20, 2026
    The Lytton First Nation has also issued an evacuation alert for some of its residents. The BC Wildfire Service says the fire is about three kilometres south of Lytton.
    Jace Maki
  • Mitchell leads Ticats to 41-27 home win over Lions June 20, 2026
    Bo Levi Mitchell won the showdown between last year's CFL outstanding player finalists.
    Globalnews Digital
  • WATCH: Global National – June 19 June 20, 2026
    Watch the full broadcast of Global National with Dawna Friesen
    Globalnews Digital
  • Calgary man with ‘horrific record for violence’ sentenced to 4 years in transit attack June 20, 2026
    Curtis Baker-Spence has been sentenced to four years for his role in the attack. With credit for time spent behind bars, he has 28 months left on his sentence.
    Elissa Carpenter
  • B.C. mayor calls FIFA a ‘bunch of arseholes’ after they reject brewery street party June 20, 2026
    Patina Brewing was planning a family-friendly block party for the Canada versus Switzerland match on Wednesday. They wanted to shut down the street.
    Taya Fast
  • Vancouver shines for Team Canada’s 1st game at BC Place: ‘This was the best’ June 20, 2026
    Victoria residents Dallas Nicholls and Nahoa Kahakauwila attended the game at BC Place and said the atmosphere inside and outside BC Place was electric.
    Amy Judd
  • Suspected illegal campfire blamed for Kalamoir Park wildfire as safety concerns remain June 20, 2026
    While the wildfire has now been extinguished, officials say significant hazards remain throughout the park, which remains closed to the public.
    Klaudia Van Emmerik
  • Environment Canada issues tornado watch for Prince George region June 20, 2026
    Environment Canada says in a Friday afternoon update that 'significant damage or destruction to infrastructure, homes and the natural environment is possible.'
    Amy Judd
  • Provincial AI strategy could protect residents, scale Sask. workforce: advocates June 20, 2026
    Advocates in Saskatchewan say a provincial artificial intelligence strategy could help protect residents and strengthen the workforce.
    Vanessa Tiberio

MALIKA KAROUM METAVERSE 2025

  • I Watched A 100x AI Developer Code… This Is Pure Insanity 🤯
    June 14, 2026 by Dr. Mfon Akpan
    I just reacted to David Ondrej’s interview with Pietro (former Anthropic engineer and founder of Magic Path), and honestly... software development will NEVER be the same.Watch as Pietro demonstrates how he uses OpenAI's Codex to automate 99% of his workflow, completely ditching traditional tools like Claude Code and Cursor. From coding entire interactive apps from […]
  • The Death of the Chatbot: Why OpenAI Just Merged ChatGPT & Codex
    June 7, 2026 by Dr. Mfon Akpan
    Everything we thought we knew about AI productivity just changed. OpenAI has officially merged its consumer ChatGPT team and its agentic-coding Codex team into a single unified platform.This isn't just a UI update—it’s the start of the "Execution Era." We are moving from AI that gives you advice to AI that does the work for […]
  • Google’s Massive AI Shift: Meet "Spark," the Agent That Works While You Sleep!
    May 31, 2026 by Dr. Mfon Akpan
    Google just changed the game at I/O 2026. Forget standard chatbots—Gemini Spark is here, and it’s a fully proactive AI agent designed to handle long-horizon tasks in the background, even when your computer is off.In this video, we break down:What is Gemini Spark and how does it differ from traditional AI?The "Antigravity" harness: How Google […]
  • Google I/O 2026: Everything You Need to Know in 10 Minutes! 🤯
    May 24, 2026 by Dr. Mfon Akpan
    Everything announced at Google I/O 2026! Get the quick summary on Android 16, the latest Gemini AI models, new smart features, and upcoming Google ecosystem updates. Don't forget to LIKE and SUBSCRIBE to stay up to date with the latest in tech!#GoogleIO2026 #Tech #Android16 #Gemini
  • Inside Thinking Machines: Next-Gen Interaction Models
    May 17, 2026 by Dr. Mfon Akpan
    How will we actually work alongside the next generation of AI? In this video, we go inside "thinking machines" to explore the next-gen interaction models that are reshaping human-AI collaboration. As AI models shift from simple chat interfaces to complex, reasoning-based systems, our approach to collaboration must scale. We break down the structural frameworks, technical […]
  • ChatGPT is BACK with SWAGGER! (The Ultimate AI Game Changer)
    May 10, 2026 by Dr. Mfon Akpan
    The wait is over—ChatGPT is back and it’s bolder than ever! In this video, we dive into the latest updates, the new "swagger" in its responses, and why this is a total game changer for creators and tech enthusiasts alike.We’re breaking down:The New Persona: How the AI's tone has shifted to be more confident and […]
  • ChatGPT Codex 5.5: The Greatest AI Coding Tool Ever? 🚀
    May 3, 2026 by Dr. Mfon Akpan
    Is this the end of manual coding?In today’s video, we are diving deep into ChatGPT Codex 5.5, the latest evolution in AI-driven development. Whether you are a seasoned software engineer or just starting your coding journey, this tool is a total game-changer for productivity, debugging, and rapid prototyping.In this video, you will learn:✅ Key Features: […]
  • GPT-5.5 IS HERE! The New OpenAI Model Everyone’s Talking About!
    April 26, 2026 by Dr. Mfon Akpan
    The wait is finally over! OpenAI has just shocked the world with the release of GPT-5.5, a next-generation frontier model that is redefine the boundaries of artificial intelligence. In this video, we break down every single major announcement from the launch, explaining exactly why this new model is the most discussed topic in technology right […]
  • DARKCODE: The Ultimate Hacking & Programming Guide (2026)
    April 19, 2026 by Dr. Mfon Akpan
    Welcome to the frontier of digital mastery. Whether you're a seasoned developer or just starting your journey into the shadows of the web, DARKCODE is your definitive roadmap to understanding the architecture of the modern world.In this comprehensive guide, we strip away the jargon to give you a clear, high-energy look at the intersection of […]
  • Meeting with Gael Gadah 📱
    April 12, 2026 by Dr. Mfon Akpan
    Most businesses do not fail overnight. They bleed slowly from bad decisions, weak systems, and no clear strategy.In this episode, I sit down with Gael Gadah to break down what it really takes to turn a struggling business around. This is not theory. This is execution.We talk about: • How to identify what is actually […]
News Portal | Theme: News Portal by Mystery Themes.