HomeSecurityRoaming Mantis Android malware campaign appears in Europe

Roaming Mantis Android malware campaign appears in Europe

The Roaming Mantis SMS phishing campaign has also appeared in Europe, as researchers identify campaigns targeting Android and iPhone users in Germany and France with malicious apps and phishing pages.

Roaming Mantis

See also: Custom malware allowed hackers to remain undetected within a network for 250 days

Roaming Mantis is a credential theft and malware distribution campaign that uses SMS phishing (smishing) to distribute malicious Android apps as individual APK files outside of the Google Play Store.

Over the past four years, the campaign has been in constant development and first appeared in 2018, targeting Android smartphone users in Japan via DNS hacking.

It later evolved to target iOS users with phishing pages to steal credentials and expand the targeted countries to include Taiwan and Korea.

Fake shipping texts

In its most recent form, Roaming Mantis uses a trojan named "Wroba" and targets users in France and Germany with smishing messages and landing pages that are inserted into compromised legitimate sites.

Wroba's goal is to steal e-banking credentials and, like other similar trojans, it spreads automatically using SMS phishing texts to people in the infected device's contacts.

The infection chain begins with the arrival of an SMS text on the target device, which contains a short warning message about a sent package with an included URL.

Roaming Mantis

If the URL is clicked from an Apple device, the victim is redirected to a phishing page, where it attempts to steal the user's Apple login credentials.

However, if the victim is using an Android device, they are taken to a landing page that asks them to install malware disguised as an Android app.

See also: Mars Stealer malware: New variant of Oski malware

The personalized applications containing Wroba are mainly for Google Chrome, but they also emulate the Yamato and ePOST transport applications.

Below are download statistics from one day in September 2021, counting tens of thousands of malicious APK downloads in Europe.

Roaming Mantis Android malware campaign appears in Europe

Now it steals your pictures and videos

Compared to previous variants, the Wrogba loader and payload have evolved and are now written in Kotlin, a language with excellent interoperability with Java.

The backdoor includes 21 malicious commands that can be executed by the attacks, while two new ones have been added in recent campaigns. These new commands are “get_gallery” and “get_photo”, which are intended to steal the victim’s photos and videos and upload them to the attacker’s servers.

Roaming Mantis

Kaspersky explains that threat actors can use the addition of these two new commands for financial fraud, identity theft, blackmail, and extortion if sensitive media is stolen.

What to do to avoid Mantis

To prevent Roaming Mantis or other Android malware from infecting your device, you should always avoid downloading APKs from unusual sources and never allow the installation of packages from unknown sources.

Additionally, SMS texts containing URLs should always be treated with caution and suspicion, even if they come from someone you know.

See also: Microsoft: Mac malware UpdateAgent is becoming increasingly dangerous

Finally, an Android internet security tool from a reputable vendor could help flag these URLs as they are visited, as analysts are actively monitoring these campaigns.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS