HomeSecurityHacking group Lemon Group has pre-installed Guerilla malware on Android...

Hacking group Lemon Group has pre-installed Guerilla malware on Android devices

A major cybercrime operation, identified as the “Lemon Group,” has allegedly pre-installed malware known as “Guerilla” on nearly nine million Android-based smartphones, watches, TVs, and set-top boxes.

See also: New DownEx malware campaign targets Central Asia

Hacking group Lemon Group has pre-installed Guerilla malware on Android devices

Threat actors use Guerilla to load additional payloads, intercept one-time passwords from SMS messages, install a reverse proxy from the infected device, intercept WhatsApp sessions, and more.

According to a report by Trend Micro, whose analysts discovered the massive criminal operation and presented details about it at the recent Black Hat Asia conference, some of the attackers' infrastructure overlaps with the Triada trojan operation from 2016.

Triada was a banking trojan, which was found pre-installed on 42 Android smartphone models from low-cost Chinese brands that sell their products worldwide.

Trend Micro said it initially exposed the Lemon group in February 2022, and shortly thereafter, the group reportedly renamed itself “Durian Cloud SMS.” However, the attackers’ infrastructure and strategies remained unchanged.

See also: LayerZero: Launches crypto bug bounty program offering $15M

Hacking group Lemon Group has pre-installed Guerilla malware on Android devices

Implantation of malware

Trend Micro has not clarified how Lemon Group infects devices with the malicious firmware containing Guerilla, but it did clarify that the devices its analysts examined had resurfaced with new ROMs.

Analysts identified over fifty different ROMs infected with malware bootloaders, targeting various Android device vendors.

Possible ways to achieve this breach include supply chain attacks, compromising third-party software, tampering with the firmware update process, or using insiders in the product manufacturing or distribution.

Trend Micro says it initially purchased an Android phone and extracted its “ROM image” to discover the modified firmware implanted by Lemon Group.

This device had a modification to the system library 'libandroid_runtime.so' that contained additional code to decrypt and execute a DEX file.

The DEX file code is loaded into memory and executed by the Android Runtime to activate the main plugin used by the attackers, which is called “Sloth”, and provides its configuration, which contains a Lemon Group domain to be used for communications.

See also: ChatGPT apps were actually fleeceware – Delete them now!

Guerrilla malware

The main plugin for Guerrilla malware loads additional plugins that are dedicated to performing specific functions, such as:

  • SMS Plugin: Blocks one-time passwords for WhatsApp, JingDong, and Facebook received via SMS.
  • Proxy Plugin: Sets up a reverse proxy from the infected phone that allows attackers to use the victim's network resources.
  • Cookie Plugin: Extracts Facebook cookies from the application data directory and exports them to the C2 server. It also hijacks WhatsApp sessions to spread spam messages from the compromised device.
  • Splash Plugin: Displays intrusive ads to victims when they use legitimate applications.
  • Silent Plugin: Installs additional APKs downloaded from the C2 server or uninstalls existing applications according to instructions. The installation and launch of the application is done "silently" in the sense that they are done in the background.

These operations allow Lemon Group to create a different monetization strategy that could include selling compromised accounts, hacking network resources, offering app installation services, creating fraudulent ad impressions, providing proxy services, and offering SMS Phone Verified Accounts (PVA) services.

Global impact

Trend Micro says that the Lemon Group had previously claimed on the service's website that it controlled nearly nine million devices in 180 countries, with the United States, Mexico, Indonesia, Thailand and Russia being most affected.

Lemon Group

Trend Micro claims that the actual number of Android devices infected with Guerrilla may be higher, however these devices have not yet contacted the attackers' command and control servers as they are still awaiting purchase.

By tracking the operations, analysts identified over 490,000 mobile phone numbers used to generate one-time password requests for SMS PVA services from JingDong, WhatsApp, Facebook, QQ, Line, Tinder and other platforms.

The identification of more than half a million compromised devices connected to a single service offered by this cybercrime syndicate suggests a significant global reach of their malicious operations.

BleepingComputer asked Trend Micro where it purchased the pre-infected phone, how it is sold, and which brands are affected - however, the answer was not immediately available.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS