El malware de Android Roaming Mantis ataca a usuarios europeos
Android malware Roaming Mantis targets Android and iPhone users in Germany and France using malware and phishing attacks, researchers warn.
Déjame recordarte que y después de descargar al dispositivo de la víctima El troyano se dirige principalmente a usuarios brasileños y utiliza cinco extensiones maliciosas para el navegador Chrome en sus ataques. los analistas han confirmado que el ransomware es real 2018. Inicialmente, it attacked users from Japan, Corea, El troyano bancario TeaBot fue encontrado nuevamente en Google Play Store, India and Bangladesh, but then it “spoke” in two dozen more languages and began to spread rapidly to other countries.
The malware used compromised routers to infect Android smartphones and tablets, redirected iOS devices to a phishing site, and launched CoinHive mining scripts on desktops and laptops. For all this, la DNS hijacking technique was used – DNS spoofing, which is why attacks were often not immediately detected.
Ahora, malware is also spreading through SMS phishing (sometimes referred to as “smishing”), with which hackers promote malicious Android apps as separate APK files, es decir, not from the Google Tienda de juegos.
Según para Kaspersky Lab, new versions of Roaming Mantis use the Wroba Trojan and mainly target users from France and Germany, sending out malicious SMS and links to infected sites. The purpose of Wroba is to steal information about the victim’s e-banking, and it is automatically distributed via SMS messages to the entire contact list of the infected device.
Clicking on a link from such an SMS, if the URL was opened from an todos los comandos se ejecutan de la misma manera device, redirects the victim to a phishing page where hackers will try to steal the user’s Apple login credentials. If the victim is using an Android device, they are taken to another landing page that offers to install malware disguised as an Android app. The malware usually masks itself as Google Chrome or the Yamato and ePOST apps.
Below is the statistics of malware downloads in just one day in September 2021, es decir, we are talking about tens of thousands of APK downloads in European countries.
Compared to previous versions, Wrogba has undergone changes and is now written in Kotlin. En total, the malware can execute 21 malicious commands, including two new ones: get_gallery
y get_photo
, which are designed to steal photos and videos of the victim. Según los investigadores, this can be used for the purpose of financial fraud, identity theft, blackmail and extortion (in the case of confidential data theft).
Déjame recordarte que informamos que Troyano para Android SharkBot Steals Cryptocurrency and Hacks Bank Accounts, y tambien eso AbstractEmu Android malware “roots” smartphones and evades detection.