Saturday, February 8, 2025
Homecyber securityBeware of FluBot Android Malware that Targets Android Users Via SMS

Beware of FluBot Android Malware that Targets Android Users Via SMS

Published on

SIEM as a Service

Follow Us on Google News

The cybersecurity researchers of Finland Aino-Maria Vayrynen of the National Cybersecurity Center have recently published a “severe alert” to notify the country’s Android users regarding a huge malicious campaign.

In this malicious campaign, the Android users were being attacked with FluBot banking malware launched via text messages sent from negotiated devices.

However, this is not the first time when FluBot has initiated any campaign, as it is being stated that this campaign is the second-largest FluBot campaign that attacked Finland.

This type of malware attack is remarkably unusual and very dangerous, in this campaign, a group of text messages are being sent by the attackers.

Banking Malware goes Global

After investigating the malware attack, the experts came to know that this malware has been active since 2020. Its main motive is to steal all the following details from the victim’s devices:- 

  • Banking credentials
  • Payment information
  • Text messages
  • Contacts

At first, the threat actors have targeted the Android users of Spain along with several other European countries, and now they have targeted the Android users of Finland.

Organizations Encouraged to Inform their Personnel

The experts of NCSC-FI issued a yellow alert, which implies some general actions are to be taken by the users as soon as possible. They have notified the users by saying that if they receive a scam message, do not click on the link, and do not download the file shared through the link.

However, the situation needs to get handled as soon as possible; that’s why it is also important for organizations to understand what data the phones might have contained so that they can assess the risks because FluBot generally steals data from phones.

Recommendations

After investigating the whole malware attack, the experts suggested some general measures that are to be followed by the users; thus, we have mentioned below:

  • Always remember to perform a factory reset on your device.
  • Remember to contact your bank if you use a banking application or handle credit card information on your device.
  • If you encounter any financial losses that report them to the police.
  • Always reset your passwords on any services that you have used with the device.
  • Lastly, contact your operator, as the threat actors might use your subscription to send text messages subject to a charge.

The information security adviser at the NCSC-FI, Aino-Maria Väyrynen stated:-

“We managed to almost completely eliminate FluBot from Finland at the end of summer thanks to cooperation among the authorities and telecommunications operators. The currently active malware campaign is a new one, because the previously implemented control measures are not effective.”

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

UK Pressures Apple to Create Global Backdoor To Spy on Encrypted iCloud Access

United Kingdom has reportedly ordered Apple to create a backdoor allowing access to all...

Autonomous LLMs Reshaping Pen Testing: Real-World AD Breaches and the Future of Cybersecurity

Large Language Models (LLMs) are transforming penetration testing (pen testing), leveraging their advanced reasoning...

Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks

Semantic communication systems, powered by Generative AI (GAI), are transforming the way information is...

Cybercriminals Target IIS Servers to Spread BadIIS Malware

A recent wave of cyberattacks has revealed the exploitation of Microsoft Internet Information Services...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

UK Pressures Apple to Create Global Backdoor To Spy on Encrypted iCloud Access

United Kingdom has reportedly ordered Apple to create a backdoor allowing access to all...

Autonomous LLMs Reshaping Pen Testing: Real-World AD Breaches and the Future of Cybersecurity

Large Language Models (LLMs) are transforming penetration testing (pen testing), leveraging their advanced reasoning...

Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks

Semantic communication systems, powered by Generative AI (GAI), are transforming the way information is...