---
title: "SMS OTP Authentication: Not As Safe As You May Think"
description: SMS One-Time-Password was a strong authentication process when it was first introduced, but it is nowadays easily bypassed by mobile apps.
image: https://blog.pradeo.com/hubfs/sms-otp-security-pradeo.png
---

[![pradeo\_logo\_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Mobile Application Security](https://blog.pradeo.com/topic/mobile-application-security)

# SMS OTP Authentication: Not As Safe As You May Think

![Picture of Roxane Suau](https://blog.pradeo.com/hubfs/roxane-suau.jpg)

 By [Roxane Suau](https://blog.pradeo.com/author/roxane-suau) on February, 17 2020

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![sms-otp-security-pradeo](https://blog.pradeo.com/hubfs/sms-otp-security-pradeo.png)

Most online transactions require a two-step authentication, and the **One-Time-Password (OTP)** sent by SMS is often one of those two steps. The purpose of an OTP is to prevent fraud by confirming that the person making the transaction and the credit card owner are one and the same. To do so, a temporary code is automatically sent by SMS to the phone number associated with the bank account used.

 

 

Once the OTP SMS is received, the user types it in the transaction interface and he is only then able to finalize his purchase. But is the mobile device (tablet or smartphone) used to send and receive an SMS innocuous? Regrettably, not very. What seemed to be like a strong authentication process when it was first introduced is nowadays easily bypassed by mobile apps.

Our team identified two kinds of mobile applications using the OTP interception technique: the legitimate ones and the malicious ones. While a safe app will intercept a SMS OTP to facilitate transactions and make them fast, a malicious app will intercept it in order to commit banking fraud.

 

## Different Purposes, Same Mechanism

![SMS-OTP-mechanism.png](https://blog.pradeo.com/hs-fs/hubfs/SMS-OTP-mechanism.png?width=552&name=SMS-OTP-mechanism.png)

 

## The same permissions are required

The more permission an app requires, the more suspicious it looks. However, an OTP interception only requires two permissions to be executed, and one of them (Internet access) is a very common one. As a consequence, apps featuring OTP interception for a malicious purpose do not appear as suspicious at first sight.

- **Permission to intercept SMS:** 'android.permission.RECEIVE\_SMS'
- **Permission to send the content, using internet or an SMS:** 'android.permission.INTERNET' **or** 'android.permission.SEND\_SMS'

 

 

## A weak spot for applications stores

The Google Play and the Apple App Store perform first-level checks to prevent **malwares** from entering their stores. However, the lack of depth of these security scans often lets malicious apps to pass through thanks to the system limits. It is even truer when the first visible layers of an app, the permissions and functions, are not giving any indication about its true nature.

An OTP interception mechanism can be used by both legitimate apps and malwares. As a result, it has the capacity to successfully pass stores’ standard security checks.

 

 

## Case study

**App name:** Postbank Finanzassistent (An [impostor app](https://blog.pradeo.com/impostor-apps-android-users-at-risk) that mimics the official German PostBank’s one)

**sha1:** 32f85c91e5a1437e93128203c27cd8eeb8bbea19

 

**This app intercepts SMS OTP in two steps:**

**1 –** Interception of SMS with the implementation of an android.content.BroadcastReceiver (org.slempo.service.MessageReceiver)

**2 –** SMS content sending via (Lorg/slempo/service/MainService) and more precisely using a java.lang.Runnable (org.slempo.service.a.a$1)

 

**1 - Interception via BroadcastReceiver**

**Required permission**: 'android.permission.RECEIVE\_SMS'

A Broadcast Receiver (MessageReceiver) is used to intercept incoming SMS with the 'onReceive' method.

**Name of the Broadcast Receiver :**

*.class public Lorg/slempo/service/MessageReceiver;*

*.super Landroid/content/BroadcastReceiver;*

 

**Method :**

*.method public onReceive(Landroid/content/Context;Landroid/content/Intent;)V*

 

**Description :**

(\*) This method calls a(Landroid/content/Intent;)Ljava/util/Map to access the SMS

*invoke-static {p2}, Lorg/slempo/service/MessageReceiver;-\>a(Landroid/content/Intent;)Ljava/util/Map;*

(\*) then calls the method b(Landroid/content/Context;Ljava/lang/String;Ljava/lang/String;)V which formats the information into JSON.

i*nvoke-static {p1, v1, v0}, Lorg/slempo/service/a/f;-\>b(Landroid/content/Context;Ljava/lang/String;Ljava/lang/String;)V*

(-) method that calls the constructor \<init\>(Ljava/lang/String;Lorg/slempo/service/a/a$a;Landroid/content/Context;)V which saves the information in the field:  Lorg/slempo/service/a/a;-\>a:Ljava/lang/String;

*invoke-direct {v0, v1, v2, p0}, Lorg/slempo/service/a/a;-\>\<init\>(Ljava/lang/String;Lorg/slempo/service/a/a$a;Landroid/content/Context;)V*

         

**2 - Data sending**

**Service name:**

*.class public Lorg/slempo/service/MainService;*

*.super Landroid/app/Service;*

**This method instantiate the runnable MainService$1:**

*.method public onCreate()V*

 

(\*) creation of Lorg/slempo/service/MainService$1

*new-instance v1, Lorg/slempo/service/MainService$1;*

              *  invoke-direct {v1, p0},*

*                Lorg/slempo/service/MainService$1;-\>\<init\>(Lorg/slempo/service/MainService;)V*

 

**Runnable Name:**

*.class Lorg/slempo/service/MainService$1*

*.implements Ljava/lang/Runnable;*

 

**Method Name:**

*.method public run()V*

 

**The call is made in the method run() **

(\*) invoke-static {v0}, Lorg/slempo/service/a/f;-\>a(Landroid/content/Context;)V

(-) Lorg/slempo/service/a/a;-\>a()V that runs Runnable Lorg/slempo/service/a/a$1

 

**Runnable Name:**

*.class Lorg/slempo/service/a/a$1;*

*.implements Ljava/lang/Runnable;*

 

**Method Name:**

*.method public run()V*

 

**(\*) Sending via http**

**Permission:** 'android.permission.INTERNET'

*invoke-static {v0, v2, v3, v4},                                                                 *

*Lorg/slempo/service/a/a;-\>a(Lorg/slempo/service/a/a;Landroid/content/Context;Ljava/lang/String;Ljava  
/lang/String;)Lorg/apache/http/HttpResponse;*

 

**(\*) Invisible SMS sending**

**Permission:** 'android.permission.SEND\_SMS'

*invoke-static {v0, v2},*

*Lorg/slempo/service/a/h;-\>a(Ljava/lang/String;Ljava/lang/String;)Z*

 

---

 

Discover Pradeo Security solution suite:

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-protection)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)<https://www.pradeo.com/en-US/mobile-threat-protection>
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence)

 

###### About The Author

[More from this author](https://blog.pradeo.com/author/roxane-suau)

![](https://blog.pradeo.com/hs-fs/hubfs/roxane-suau.jpg?height=100&name=roxane-suau.jpg)

###### Roxane Suau

#### Recommended articles

[![Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/hubfs/Template%20article%20(32)-1.png)](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

###### [Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- June 18, 2026

[![Cyber Resilience Act: The first obligations take effect in September 2026](https://blog.pradeo.com/hubfs/Template%20article%20(26)-1.png)](https://blog.pradeo.com/cyber-resilience-act-the-first-obligations-take-effect-in-september-2026)

###### [Cyber Resilience Act: The first obligations take effect in September 2026](https://blog.pradeo.com/cyber-resilience-act-the-first-obligations-take-effect-in-september-2026)

 \- May 7, 2026

[![What is Application Shielding?](https://blog.pradeo.com/hubfs/Template%20article%20(6)-1.png)](https://blog.pradeo.com/what-is-application-shielding)

###### [What is Application Shielding?](https://blog.pradeo.com/what-is-application-shielding)

 \- March 5, 2026

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[Fence integrates Pradeo's technology to secure its clients' mobile fleets](https://blog.pradeo.com/fence-integrates-pradeos-technology-to-secure-its-clients-mobile-fleets-1)

 \- 17 February, 2020

[RedHook: the banking trojan that grants itself system-level access on Android](https://blog.pradeo.com/redhook-the-banking-trojan-that-grants-itself-system-level-access-on-android)

 \- 17 February, 2020

[What Google's latest report reveals about mobile threats](https://blog.pradeo.com/what-googles-latest-report-reveals-about-mobile-threats)

 \- 17 February, 2020

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- 17 February, 2020

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- 17 February, 2020

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (28)](https://blog.pradeo.com/topic/news)
- [Partners (25)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Roxane Suau"
  },
  "dateModified" : "January 27, 2021, 1:48:27 PM",
  "datePublished" : "2020-02-17 08:11:53",
  "description" : "SMS One-Time-Password was a strong authentication process when it was first introduced, but it is nowadays easily bypassed by mobile apps.",
  "headline" : "SMS OTP Authentication: Not As Safe As You May Think",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://cdn2.hubspot.net/hubfs/2378615/sms-otp-security-pradeo.png"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```