HomeSecurityAndroid malware distributed via phishing SMS and steals data

Android malware is distributed via phishing SMS and steals data

Android malware

A powerful form of Android malware is back and spreading via SMS phishing attacks. The malware can steal banking details, personal information, private communications and more. It’s called FakeSpy and has been active since 2017. It initially targeted users in Japan and South Korea, but is now targeting users Android around the world. Depending on the target, the necessary changes are made to trick users across Asia, Europe and North America.

FakeSpy's latest campaign was analyzed by researchers at Cybereason, who say the attacks are linked to "Roaming Mantis," a Chinese hacking groupthat has carried out similar campaigns.

FakeSpy is constantly under development and “evolving rapidly.” New versions of the malware are released every week, with new features and evasion techniques.

Android malware acts as an information stealer. It steals SMS, financial information, app and account details, while also reading contact lists and more.

The recent campaign targets users in China, Taiwan, France, Switzerland, Germany, the UK, the US and other countries. The Android malware attempts to install itself on the victim's device via a phishing SMS, claiming to be related to a lost package from a local postal or delivery service.

SMS phishing

In the phishing SMS, there is a link that directs users to a fake website. There, they are instructed to download an app that appears to be from the local postal service. For example, users in the United Kingdom are asked to download a specially designed fake version of the Royal Mail app. In the United States, they download the US Postal Service app, in Germany, Deutsche Post, in France, La Poste, in Japan, Japan Post, in Switzerland, Swiss Post, and in Taiwan, Chughwa Post. Essentially, by downloading these apps, users are downloading Android malware.

The fake apps look very similar to the real ones. After downloading the app – which requires the user to allow installation from unknown sources – the fake page will redirect users to the legitimate website so they don’t suspect anything.

Android malware also requests a lot of permissions, which doesn't seem too surprising because it's common in legitimate apps as well.

Once installed, FakeSpy can monitor the device to steal various information: name, phone number, contacts, banking details, cryptocurrency details. It also monitors messages and applications.

The Android malware exploits the device infection to spread by sending the same phishing SMS to all of the victim's contacts.

Researchers say the attacks are not targeted. Hackers are trying to target as many users as possible to steal personal and especially banking information.

FakeSpy has been active for the past three years and continues to pose a threat to Android users as it evolves and changes.

However, users can avoid falling victim to Android malware by being extremely cautious of unsolicited SMS messages, especially if they claim to be from organizations and ask the user to open links and files. Finally, a mobile security programcan also help detect the threat.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS