Researchers have observed new attacks, including targeting Pakistan with smishing attacks and the use of the Grandoreiro banking trojan against Brazil.

Pakistan has become the latest target of a hacking group called the Smishing Triad , which until recently targeted areas mainly in the EU, Saudi Arabia, the UAE and the US .
“The group’s latest tactic involves sending malicious messages, on behalf of Pakistan Post, to mobile phone customers via iMessage and SMS,” Resecurity said in a recently published report. “The goal is to steal their personal and financial information.”
See also: Google Play: Anatsa banking trojan and malicious apps with millions of downloads
The Smishing Triad hackers are believed to speak Chinese and are using stolen databases sold on the dark web to send fake messages . They try to convince recipients to click on links, under the guise of a failed package delivery, and urge them to update their address.
Users who end up clicking on the URLs are directed to fake websites that prompt them to enter their financial details, due to an extra charge for re-delivery.
According to the researchers, in addition to Pakistan Post, the hackers also impersonated other services. For example, they targeted people who were expecting legitimate packages from reputable courier services such as TCS, Leopard, and FedEx.
See also: Android banking trojan Antidot appears as a Google Play update
At the same time, attacks have been detected by a financially motivated group based in Latin America and tracked by Google as FLUXROOT. These hackers are targeting users in Brazil with the banking trojan Grandoreiro. The company said it has taken down phishing pages hosted by the group on Google Cloud, impersonating Mercado Pago, with the aim of stealing users' credentials.
“More recently, FLUXROOT continued distributing Grandoreiro, using cloud services such as Azure and Dropbox,” he said.
See also: Grandoreiro banking trojan “returned” more powerful

Protection
- Installing antivirus software is essential for protecting your device. These software can identify and remove malware before it can cause damage .
- It's important to keep your operating system and applications up to date. Updates often include security fixes that can protect your device from malware.
- Avoid installing apps from third-party sources. apps have not undergone the same security checks as those in official stores.
- Pay attention to the permissions apps ask for. If an app asks for access to personal information that doesn't seem necessary, it may be best not to install it.
- Be wary of phishing messages that may try to trick you into downloading malware. These messages may appear to come from legitimate sources, but they often contain links or attachments that can install malware on your device.
- Finally, it is important to regularly back up your data. This can help restore your information if your device is infected with malware (e.g. Grandoreiro).
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
