The National Cyber Security Center in Finland (NCSC-FI) has warned about a massive hacking campaign targeting the Android users with the Flubot banking malware, via text messages sent from compromised devices.
This is the second large-scale Flubot campaign to hit Finland this year. During the previous attack, Finns received daily spam messages from early June to mid-August 2021.
See also: 300,000 Android users have downloaded these banking trojan malware apps

As happened over the summer, the new spam campaign asks targets to open a link that will allow them to access an answering machine message or a message from their mobile phone company.
However, SMS recipients are redirected to malicious sites that promote APK installers to deploy Flubot banking malware on Android devices .
Targets using iPhones or other devices are simply redirected to other fraudulent and potentially malicious pages, such as phishing pages that attempt to steal their credit card information.
“According to our current estimate, over 70,000 messages have been sent in the last few hours. If the current campaign is as aggressive as the one from the summer, we expect the number of messages to increase to hundreds of thousands in the coming days. There are already dozens of confirmed cases where devices have been infected,” the Finnish National Cybersecurity Center said in the warning issued on Friday.
See also: APT37 targets South Korean journalists with Chinotto malware
“We managed to almost completely eliminate the FluBot banking malware from Finland in late summer thanks to cooperation between authorities and telecommunications operators. The current malware campaign is new, because the control measures previously implemented are now not effective,” said a security consultant at NCSC-FI.

Android users who receive Flubot spam messages should not open the embedded links or download files found in these links.
Flubot Android banking malware has spread to multiple countries
Flubot banking malware (also known as Fedex Banker and Cabassous) has been active since late 2020 and is used to steal banking credentials, payment information, text messages, and contacts from infected devices.
Initially, the botnet primarily targeted Android users in Spain. However, it has now expanded to other European countries (Germany, Poland, Hungary, the United Kingdom, Switzerland) as well as users in Australia and Japan. The attacks have been observed in recent months, although police authorities reportedly arrested the gang's leaders in March.
After infecting an Android device, Flubot spreads by sending spam messages to the victim's contacts and instructing targets to install apps that contain malware.
See also: 100 million “pieces of malware” were created for Windows in 2021
Once deployed on a new device, Flubot will attempt to trick victims into granting additional permissions and access to the Android Accessibility service, allowing it to hide and perform malicious activities in the background.
It then takes control of the infected device and gains access to victims' payment and banking information via phishing pages.
Flubot banking malware can also read SMS messages, make phone calls, and monitor system notifications for application activity.

Users whose Android devices have been infected with Flubot banking malware should take the following measures:
- Perform a factory reset on the device.
- Contact the bank in case users used a banking application or provided banking information during the infection period.
- Reporting financial losses to the police.
- Reset passwords for all services accessed via the infected device.
Source: Bleeping Computer
