A new smishing (SMS phishing ) attack has been detected , where victims are urged to open a malicious link in order to cancel a potential fraud attempt.
Trend Micro researchers have discovered a new mobile threat that is spreading rapidly in Taiwan.
Cybercriminals send a text message to the victim, informing them that online electricity bill payment has been activated and providing them with a link to cancel the action. They are also given another malicious link to follow if they want to continue the action.
The link intended to cancel the action redirects the user to a mobile phone application, called Google Service Framework, which can send messages and monitor incoming calls.
Surprisingly, the app mimics a legitimate app from Google, called Google Services Framework, and the differences between the two may go unnoticed by most users.
Upon installation, the fake application requests administrative privileges and runs as a service, making its removal more complicated.
The malicious application aims to take advantage of mobile phone service transaction services, which generally require confirmation from the user via SMS.
The malware, detected as ANDROIDOS_RUSMS.A, can block messages from specific senders on the victim's phone and redirect them to a server they manage. The criminals are then able to send and intercept messages, as well as confirm the purchase on behalf of the user and therefore complete the transaction, without the victim immediately realizing it.
As we always say, be careful of links sent to us via SMS or email. The best solution is to visit the official website of any service that sends us an update directly and not follow any link provided.

