HomeSecurityHackers send SMS pretending to come from the Iranian government

Hackers send SMS pretending to be from the Iranian government

Security firm Check Point Research has uncovered a hacking campaign involving cyberattacks impersonating Iranian government agencies to infect the mobile devices of Iranian citizens via SMS messages.

SMS
Hackers send SMS pretending to be from the Iranian government

See also: Ukraine arrests hackers from the "Phoenix" group

The SMS messages urge victims to download Android apps related to official Iranian services, such as Iran's Electronic Court Services. The initial SMS messages typically claim that a complaint has been filed against the victim and that a request needs to be received to respond.

Once downloaded, the apps allow hackers to access the victim's private messages. Victims are prompted to enter their credit card details to cover a service fee, giving the attackers access to card information that they can then use. By accessing a victim's private messages, attackers can bypass two-factor authentication.

Check Point Research said the campaign is ongoing and is being used to infect tens of thousands of devices. Iranian citizens have taken to social media to complain about the scams. Some Iranian news outlets have reported on the issue.

Check Point's Shmuel Cohen said in a campaign that more than 1,000 people downloaded the malicious app in less than 10 days. Even if they didn't enter their credit card details, their device became part of the botnet.

See also: Hackers exploited flaw in popular e-commerce software

Alexandra Gofman, head of the threat intelligence team at Check Point, told ZDNet that the attacks appear to be a form of cybercrime and are not attributed to any state-backed actor.

The speed and spread of these cyberattacks is unprecedented, Gofman said, adding that it is an example of a successful campaign targeting the general public.

Check Point explained that the cybercriminals behind the attack are using a technique known as “smishing botnets. Devices that have already been compromised are used to send SMS messages to other devices.

SMS

See also: Hackers deploy Linux malware on e-commerce servers

The people behind the technique are now offering it to others on Telegram for up to $150, giving anyone with the infrastructure the ability to launch similar attacks without much effort. Although Iranian police were able to arrest one of the perpetrators, there are dozens of different cybercriminals in Iran currently using this tool.

The company estimates that most victims have had about $1,000 to $2,000 stolen. The attackers then offer the stolen personal information to others online.

Gofman added that the general population of Iran is now in a situation where cyberattacks are significantly affecting their daily lives.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS