fake login overlays , asking the user to reauthenticate or re-enter his payment card details , where appropriate . BankBot can phishAttack.Phishingfor credentials using overlays for apps such as Facebook , Viber , Youtube , WhatsApp , Uber , Snapchat , WeChat , imo , Instagram , Twitter , and the Google Play Store . This data is collectedAttack.Databreachand sent back to online servers , where the crook can accessAttack.Databreachit via a neatly arranged backend . Once the BankBot author has accessAttack.Databreachto user information , he can initiate banking transactions , or sell the user 's social media credentials online . When siphoning money out of a victim 's bank account , BankBot will also interceptAttack.Databreachand silently delete incoming SMS messages , meaning the bank 's transaction notification never reaches the user . Other BankBot features include the ability to send SMS messages and USSD requests , stealAttack.Databreachthe user 's contacts list , track the user via GPS coordinates , and request additional permissions via popups for the latest Android OS versions , where the permissions system is more layered and interactive than in previous releases .