Security firm Check Point said it has discovered an Iranian hacking group that has developed specialized Android malware capable of stealing two-factor authentication (2FA) codes sent via SMS. The malware was part of an arsenal of hacking tools developed by a hacking group nicknamed Rampant Kitten.
Check Point says the group has been active for at least six years and primarily targets Iranian minorities, anti-regime organizations, and resistance movements.
These campaigns involved the use of several different malware, including four variants of Windows infostealers and an “Android backdoor.”.

The Windows malware strains were primarily used to steal the victim's personal documents, but also files from Telegram which would allow attackers to access the victim's Telegram account.
Additionally, Windows malware strains also stole files from the password manager KeePass.

Android app with 2FA theft capabilities
But while the hackers from the Rampant Kitten group favored Windows trojans, they also developed similar tools for Android.
In a report published today, Check Point researchers said they discovered a powerful Android backdoor developed by the group. The backdoor could steal a victim's contact list and SMS messages, record what the victim says through the microphone, and display phishing.
However, the backdoor also contained tasks running at regular intervals that focused on stealing 2FA codes.
Check Point said the malware would forward to attackers any SMS message that contained the string “G-,” which is commonly used to prefix 2FA codes for Google accounts sent to users via SMS.
The thinking is: Rampant Kitten operators would use the Android trojan to display a phishing , capture the user's credentials, and then gain access to the victim's account.
If the victim had enabled 2FA, the malware's 2FA SMS interception feature would secretly send copies of 2FA messages to the attackers, allowing them to bypass 2FA.
But that wasn’t all. Check Point also found evidence that the malware would also automatically forward all incoming SMS messages from Telegram and other social networking. These types of messages also contain 2FA codes, and it’s highly likely that the group used this feature to bypass 2FA on more than just Google accounts.
While it is widely accepted that government hacking groups are usually able to bypass 2FA, we rarely have insight into tools and how they do it.
Rampant Kitten now joins the ranks of APT20, a Chinese state-sponsored hacking group that was also seen bypassing hardware-based 2FA last year.
