The creators of FluBot have launched a new campaign that uses fake Android security update warnings to trick potential victims into installing the malware on their devices.

See also: iOS 15 FaceTime: How can Android and Windows users join a call?
In a new post, New Zealand's computer emergency response team Cert NZ warned users that the message on the malware's new installation page is actually a lure designed to create a sense of urgency that misleads users into installing FluBot on their own devices.
The new FluBot installation page, which users are directed to after receiving fake messages about pending or lost package deliveries, informs them that their devices have been infected with FluBot, a form of Android spyware used to steal financial logins and password data from their devices. However, by installing a new security update, they can remove FluBot from their Android smartphone.
But the page goes a step further, instructing users to enable the installation of applications from unknown sources on their device. This way, the cybercriminals’ fake security update can be installed on their device, and while a user may think they have taken measures to protect themselves from FluBot, they have actually installed the malware on their smartphone.
See also: Facebook: Open source Android vulnerability detection tool
Change of tactics
Until recently, FluBot spread to Android smartphones via spam text messages using contacts stolen from devices already infected with malware. These messages would instruct potential victims to install apps on their devices in the form of APKs delivered from servers controlled by attackers.
Once FluBot is installed on a user's device, the malware often attempts to trick victims into granting it additional permissions as well as granting access to the Android Accessibility service which allows it to run in the background and perform other malicious tasks.
FluBot is able to steal a user’s banking information using overlay attacks where an overlay is placed on top of legitimate banking and cryptocurrency apps. As mentioned above, the malware will also steal a user’s contacts to send them phishing emails to help further spread FluBot.
See also: Android malware has stolen money from 10 million users!
While FluBot was primarily used to target users in Spain at its inception, its operators have since expanded the campaign to other countries in Europe, including Germany, Poland, Hungary, the United Kingdom, and Switzerland, as well as Australia and Japan in recent months.
Information source: techradar.com
