HomeSecurityThe Android malware of the Roaming mantis campaign has been upgraded

The Android malware of the Roaming Mantis campaign has been upgraded

The Android malware Roaming mantis has been updated with a DNS changer , which aims to compromise WiFi routers. Once compromised, it changes the router's DNS settings so that other devices can be infected when connecting to the WiFi network. In September 2022, researchers first observed the updated version of the Roaming mantis malware, which had an updated Android version of Wroba.o/XLoader to detect vulnerable routers.

See also: Hook Android malware: Learn everything about the new big threat


Roaming mantis dns changer malware

Kaspersky researchers had discovered the latest version of the Wroba.o/XLoader Android malware variant. They had been monitoring the activities of the Roaming Mantis campaign for a long time. According to them, the Roaming Mantis campaign has been using the DNS hijacking method since 2018, but the new element in the latest campaign is that the DNS changer malware targets specific router models. The current campaign targets specific models of WiFi routers used mainly in South Korea. However, this is changing and the campaign may adapt to include routers used in other countries. This tactic allows threat actors to carry out targeted attacks and compromise only specific users, avoiding detection by surrounding regions. Previous Roaming Mantis malware campaigns have targeted users in Japan, Austria, France, Germany, Turkey, Malaysia, and India.







The Android malware of the Roaming Mantis campaign has been upgraded

The new router DNS changer
In the recent Roaming Mantis malware attacks, the group used SMS phishing (smishing) to direct victims to a malicious site.
If the user’s device was running Android, they would need to install an Android APK, which would contain the Wroba.o/XLoader malware.
However, for iOS users, the page would redirect them to a phishing page with the aim of stealing their credentials.

Once the XLoader malware had finished installing on Android devices, it would have to “pull” the default gateway IP address from the connected router.
It would then attempt to access the administrator web interface using a default password to find the router model.

The Android malware of the Roaming Mantis campaign has been upgraded

XLoader now includes 113 pre-programmed strings that are used to identify specific router models.
If a match is found, the malware will proceed to “hijack” the router’s DNS settings.
Kaspersky researchers said that the Roaming Mantis malware’s DNS changer uses default login credentials (admin/admin) to gain access to the router.
It then makes changes to the DNS settings using different methods depending on the model it has detected.

Roaming mantis dns changer malware

See also: Predator inside story: SMS key to wiretapping investigation

Spreading the infection
With the router's DNS settings modified, when other Android devices connect to the WiFi network, they will be directed to the malicious site and asked to install the APK.
This creates a continuous stream of infected devices that can compromise other "clean" routers, allowing the malware to spread to even more devices.

A characteristic of the Roaming Mantis malware is that it is "intentionally untethered", which means that it can spread unchecked.
Users can protect themselves from Roaming Mantis campaigns by avoiding clicking on links received via SMS.

It is also important not to install APKs that are not on Google Play.

Source of information: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS