HomeSecurityAndroid malware CherryBlos steals passwords using OCR

CherryBlos Android malware steals passwords using OCR

New Android malware CherryBlos can steal your sensitive information using Optical Character Recognition (OCR), a technology commonly used to extract text from images.

See also: Android: Code update makes n-days just as dangerous as zero-days

CherryBlos Android malware steals passwords using OCR

Recently, Trend Micro discovered two new malware families, called CherryBlos and FakeTrade, which use the same infrastructure and certificates, suggesting that they may have been created by the same person or group of people.

CherryBlos was first detected earlier in April this year and was distributed in APK format, acting as either an AI tool or a coin miner. It was often presented as GPTalk, HappyMiner, Robot999, and SnythNet to hide its true nature.

The malware uses Android's accessibility service, which protects it from damage, and often uses fake user interfaces that resemble official apps to steal passwords.

See also: The race against time in ransomware attacks

CherryBlos can also use OCR (Optical Character Recognition) to read text from images stored on the device. When setting up a new cryptocurrency wallet, many people often take a photo of their recovery codes and save them on their devices.

The malware can potentially use OCR to read and extract the recovery code, which can then be used to gain access to your crypto wallet.

If you are a Binance user, CherryBlos can also change the crypto recipient address to the attacker’s, while keeping the original address unchanged for the user. This allows her to redirect and steal the funds being transferred.

See also: Ukrainian hackers troll Russian navy, send malware to their phones

Trend Micro claims that the “FakeTrade” campaign was the work of 31 apps that used the same network and certificate as CherryBlos. They tricked users into watching ads , signing up for premium subscriptions , and filling up the apps ’ digital wallets without allowing them to claim rewards.

These malicious apps used multiple distribution channels such as Telegram, Twitter , and YouTube and were even available on the official Android app store – Google Play.

Source of information: indianexpress.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS