HomeSecurityRedDrop malware: Beware, it inflates accounts and is circulating

RedDrop malware: Beware, it inflates accounts and is circulating

RedDrop malware: After all these years of blogging, we can proudly say that we have never used terms like “Caution” in headlines without a good reason. The recently discovered RedDrop malware for Android is a very good reason.
The malware works “underground” stealing sensitive data from infected devices (including recorded phone calls) and storing them in Cloud storage accounts.red drop
But it doesn’t just do that…
RedDrop works like eavesdropping spyware, collecting information from the device, but also recordings of the victim’s environment, along with all the data included on the device: photos, contacts, notes, saved Wi-Fi networks and nearby hotspots.
Researchers from security firm Wandera, who uncovered it, refer to it as “one of the most sophisticated malware for Android”. Once RedDrop is installed, no one realizes that their device is infected until they receive the first bill…
The malware secretly sends SMS messages to a service that charges them, in addition to all the spyware activities we mentioned above. The security firm says that the malware is so smart that immediately after sending an SMS, it carefully hides all evidence of the messages that have been sent.RedDrop malware: Beware, it inflates accounts and is circulating
In total, 53 applications have been discovered that are used to distribute the malware.
These applications that distribute RedDrop include: Space Game Free, Video Blocker, Cosmos FM, Plus Italy, Paint It Hot Tone and Ninja Slice. None of these applications come from the official Google Play Store, but from third-party stores.
However, to direct the user to the malware, researchers found that the scammers use a complex network containing over 3,000 domains that are connected to each other in an attempt to bypass and prevent detection techniques to increase the chances of the malware being successfully installed on a device.
The initial download is simply a dropper, which when opened and run, will connect to a command and control (C&C) server to download additional files.
Once installed, the spyware begins collecting the data mentioned above and stores it in Dropbox or Google Drive. At the same time, it also starts using SMS sending.
The combination of these actions is extremely destructive, both for the victim’s privacy and their financial situation.
It is currently unknown what the RedDrop team's exact goal is (apart from the obvious financial gain), but their interest in stealing data and audio recordings from infected devices suggests an interest in espionage. It appears that the team also has enough manpower to develop a large number of applications and maintain sophisticated malware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS