
Security researchers have discovered new distribution campaigns of FluBot and TeaBot malware. The malware is distributed primarily through smishing attacks and malicious applications that primarily target Android users in Germany, Poland, Spain, Romania, and Australia.
See also: LockBit ransomware: Linux version targets VMware ESXi servers
FluBot malware
The themes used in malicious SMS (smishing) to distribute the FluBot malware include fake messages from supposed courier companies, questions like “Are you in this video?”, fake browser updates, and fake voicemail notifications.

Researchers from Bitdefender Labs discovered the latest FluBot campaign, during which over 100,000 malicious SMS messages were sent since December 2021.
According to the researchers' report, FluBot malware operators carry out attacks using different baits for each country.
Once a device is infected, the malware uses the victim's contact list to distribute more malicious SMS messages. These new messages (sent to contacts) are sent by the original victims, so recipients are more likely to fall for the trap, since they trust the sender. This way, attackers can achieve even more infections.
See also: German government: APT27 group breaches business networks
Attacks aimed at distributing the FluBot malware began in 2021 and continue to target a large number of Android users, indicating that the attackers do not intend to stop their malicious activities anytime soon.
TeaBot malware
TeaBot is a different Android banking trojan that was discovered in January last year and targets users around the world.
According to Bitdefender, TeaBot has appeared several times in the Play Store since December 2021.

Researchers say that TeaBot is distributed through trojanized apps on the Google Play Store. Some of the malicious apps are:
- QR Code Reader – Scanner App – 100,000 downloads
- QR Scanner APK – 10,000 downloads
- QR Code Scan – 10,000 downloads
- Smart Cleaner – 1,000 downloads
- Weather Cast – 10,000 downloads
- Weather Daily – 10,000 downloads
The attackers promoted these apps by paying to appear on Google Ads.
After being installed and running on the victim's device, the apps secretly check the country code and stop if they see that it is Ukraine, Uzbekistan, Uruguay, or the United States.
In another case, victims are infected with a variant of the TeaBot malware. At the same time, the applications prompt users to allow the installation of packages from third-party sources.
See also: Chaes banking trojan: Affects Chrome with malicious extensions
From December 6, 2021 to January 17, 2022, Bitdefender analysts had discovered 17 different versions of the TeaBot malware, which infect devices through malicious applications.
The TeaBot campaign shows that even when you install software from the Google Play Store, you're not always safe.
You should be careful when installing a new app. Before doing anything, you should check other users' reviews and the permissions the app requests.
Source: Bleeping Computer
