Android trojan embedded in a flashlight widget app. When a user opens certain apps, such as those for social media or banking, the malware overlays a fake login page on top of the legitimate app to steal the user’s credentials. It can also bypass two-factor authentication by intercepting SMS messages.

