Καταργήστε τον ιό KQGS Ransomware

Κυβερνασφάλεια, where it posed as a QR code reader (QR Code & BarcodeScanner) and managed to spread to more than 10,000 συσκευές. The malware targets users of more than 400 banking and financial applications, including those from Russia, China, and the United States.

According to a report from Cleafy, TeaBot-infected applications act as droppers. Αυτό είναι, they get to the Google Play Store without malicious code and request minimal permissions from the user, so that it is difficult for reviewers and Google’s automated checks to detect anything suspicious.

Επιπλέον, trojanized applications actually work, delivering the promised functionality, so the reviews about them are mostly positive.

Κυβερνασφάλεια

Για παράδειγμα, QR Code & Barcode – Scanner that was discovered in February, looked like a regular utility for scanning QR codes. Ωστόσο, once installed, the app requested an update via a pop-up message, and instead of the standard procedure set by the Play Store rules, the update was downloaded from an external source.

The experts traced the source of these downloads to two GitHub repositories owned by the user feleanicusor and containing several samples of the TeaBot malware, uploaded on February 17, 2022.

Κυβερνασφάλεια
Attack scheme

Once thisupdateis complete, TeaBot is downloaded to the victim’s device as a new QR Code Scanner: Add-On application. This application starts automatically and requests the rights to use Accessibility Services to perform the following functions:

  1. view the device screen and create screenshots that show login credentials, two-factor authentication codes, SMS content, και ούτω καθεξής;
  2. automatic granting of additional permissions to malware in the background, which does not require user intervention.

Κυβερνασφάλεια

Με ενδιαφέρο, earlier versions of TeaBot, discovered in January 2021 and studied by Bitdefender, exited if they detected that the victim was in the United States. Now TeaBot also attacks users from the United States, and also received support for Russian, Slovak and Chinese languages, αυτό είναι, the malware attacks any users without making exceptions.

Επίσης, compared to samples from early 2021, the malware is now more obfuscated, and the number of its target applications has increased by 500% – from 60 προς το 400. These include banking and insurance applications, as well as cryptocurrency wallets and exchange solutions cryptocurrencies.

Επιτρέψτε μου να σας υπενθυμίσω ότι το γράψαμε και αυτό TeaBot TeaBot κακόβουλο λογισμικό στο Google Play Store, και αυτό AbstractEmu Το κακόβουλο λογισμικό Android «ριζώνει» smartphone και αποφεύγει τον εντοπισμό.

Helga Smith

Ενδιαφέρομαι πάντα για τις επιστήμες των υπολογιστών, ειδικά την ασφάλεια δεδομένων και το θέμα, που ονομάζεται σήμερα "επιστημονικά δεδομένα", από τα πρώτα μου χρόνια. Πριν μπείτε στην ομάδα κατάργησης ιών ως αρχισυντάκτης, Εργάστηκα ως ειδικός στον τομέα της ασφάλειας στον κυβερνοχώρο σε πολλές εταιρείες, συμπεριλαμβανομένου ενός από τους εργολάβους της Amazon. Μια άλλη εμπειρία: Έχω διδάξει σε πανεπιστήμια Arden και Reading.

Αφήστε μια απάντηση

Αυτό το site χρησιμοποιεί Akismet να μειώσει το spam. Μάθετε πώς γίνεται επεξεργασία των δεδομένων σας σχόλιο.

Κουμπί Επιστροφή στην κορυφή