Wednesday, April 2, 2025
HomeAndroidHackers Spread Android Malware Via Coronavirus Safety App & Gain Contacts Access...

Hackers Spread Android Malware Via Coronavirus Safety App & Gain Contacts Access to Infect All of Them via SMS

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new Coronavirus safety Android App that infects Android users via malware, as a result, it hefty usage charges for victims.

Attackers taking advantage of the Coronavirus fear to continuously exploit online users by infecting their mobile with various tactics and techniques.

An App called “Corona Safety Mask” that is spread via the malicious domain ” hxxp://coronasafetymask.tk” and force users to install the APK in their Android to receive a Free Corona safety mask.

Coronavirus Safety Mask App
App Name:Corona Safety Mask
Package:com.coronasafetymask.app
Hash:d7d43c0bf6d4828f1545017f34b5b54c
Virus Total:13/64

Infection Process

Once the app downloaded from the attacker’s website and installed in the victim’s Android device, it requests permission to read contacts and send SMS messages.

Coronavirus Safety Mask App

After the app gets installed, users to click a button that leads to an online portal where users can buy the Masks.

Users ask to pay online to purchase the mask, in the background, attackers steal the credit/debit card information.

According to the Zscalar research “Along with all the above activities, an important functionality takes place behind the scenes. The app checks whether it has already sent SMS messages or not. If it has not, it collects all the victim’s contacts.

After collecting all the contact information from the victim’s mobile, it sends a download link to all of them via SMS to spread itself to more users.

Coronavirus Safety Mask App
SMS sending functionality

Eventually, all the contacts received an SMS with the following information ” “Get safety from corona virus by using Face mask, click on this link download the app and order your own face mask – hxxp://coronasafetymask.tk

Coronavirus Safety Mask App

By sending itself to a victim’s contact list, this malicious app aims to spread itself over and over. Researchers believe the app is in its early stages and this (and other) functionalities will be added as the app is updated.

Also Read: Beware of Android Coronavirus Tracker app that Lock’s Your Device & Asks Ransom Payment

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Google Cloud Platform Vulnerability Exposes Sensitive Data to Attackers

A privilege escalation vulnerability in Google Cloud Platform (GCP), dubbed "ImageRunner," was recently discovered...

Apple Fined $162 Million by France Authorities for Mobile Ad Market Domination

French antitrust regulators have imposed a hefty fine of €150 million ($162.4 million) on...

20,000 WordPress Sites at Risk of File Upload & Deletion Exploits

A critical security alert has been issued to WordPress site administrators following the discovery...

Prince Ransomware – An Automated Open-Source Ransomware Builder Freely Available on GitHub

The cybersecurity landscape has witnessed a concerning development with the emergence of "Prince Ransomware,"...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Prince Ransomware – An Automated Open-Source Ransomware Builder Freely Available on GitHub

The cybersecurity landscape has witnessed a concerning development with the emergence of "Prince Ransomware,"...

QR Code Phishing (Quishing) Attack Your Smartphones To Steal Microsoft Accounts Credentials

Cybersecurity researchers have identified a growing trend in phishing attacks leveraging QR codes, a...

North Korea IT Workers Expand Their Employment Across Europe To Infiltrate the Company Networks

North Korean IT workers have intensified their global operations, expanding their employment footprint across...