Cybercriminals attempting to compromise iOS & Android devices via advanced Phishing campaign that redirect iOS users to a malicious landing page which allows attackers to collect sensitive information and the Android users are compromised with malware via Hijacked WiFi Routers.
Researchers believe that the attack belongs to Roaming Mantis campaign that uses DNS hijacking attack to hack Android smartphones, current attack carries updates on their tools and tactics.
In order to compromise iOS devices and to collect the data, attackers let
iPhone user visits a new landing page where the user forced to download the malicious iOS mobile config installation.
After the installation process, users redirect into the phishing site that automatically opens in a web browser and collected information from the device will be sent to the attacker’s server.
Once users enter their credentials then it redirects to the next page, which tried to steal the two-factor authentication code (PIN) sent to the device.
Researchers discovered another malicious APK which is a variant of sagawa.apk, a malware that was earlier distributed via SMS in Japan.
According to Kaspersky, We also found out that the threat actors had compromised WiFi routers to overwrite DNS settings and discovered that the following two features were updated as well to compromise Android devices.:
This new campaign affected many countries includes Russia, Japan, India, Bangladesh, Kazakhstan, Azerbaijan, Iran and Vietnam
Also, researchers detected this malware over 6,800 times for over 950 unique users during this period.
417a6af1172042986f602cc0e2e681dc | APK file |
651b6888b3f419fc1aac535921535324 | APK file |
0a4e8d3fe5ee383ba3a22d0f00670ce3 | APK file |
870697ddb36a8f205478c2338d7e6bc7 | APK file |
7e247800b95c643a3c9d4a320b12726b | \classes.dex |
7cfb9ed812e0250bfcb4022c567771ec | \classes.dex |
8358d2a39d412edbd1cf662e0d8a9f19 | \classes.dex |
7cfb9ed812e0250bfcb4022c567771ec | \classes.dex |
af2890a472b85d473faee501337564a9 | Decrypted dex file |
c8d7475a27fb7d669ec3787fe3e9c031 | Decrypted dex file |
d0848d71a14e0f07c6e64bf84c30ee39 | Decrypted dex file |
e2b557721902bc97382d268f1785e085 | Decrypted dex file |
Course: Learn Malware Analysis – Advance Malware Analyst Bundle
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.
The Tails Project has urgently released Tails 6.14.2, addressing critical security vulnerabilities in the Linux kernel…
Check Point Research (CPR) has uncovered a new targeted phishing campaign employing GRAPELOADER, a sophisticated…
A sophisticated cyber espionage campaign leveraging the newly identified BRICKSTORM malware variants has targeted European…
A recent report by Cyble has shed light on the evolving tactics of hacktivist groups,…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released nine new advisories detailing severe…
Email security solutions are critical for protecting organizations from the growing sophistication of cyber threats…