{"id":4724,"date":"2024-07-31T07:00:00","date_gmt":"2024-07-31T12:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/endpoint-security\/dynamically-evolving-sms-stealer-threatens-global-android-users"},"modified":"2024-07-31T07:00:00","modified_gmt":"2024-07-31T12:00:00","slug":"dynamically-evolving-sms-stealer-threatens-global-android-users","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/31\/dynamically-evolving-sms-stealer-threatens-global-android-users\/","title":{"rendered":"Dynamically Evolving SMS Stealer Threatens Global Android Users"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte478261f3b5c9a29\/66a914a93d842b4a874b41af\/androidmalware_rafapress_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A novel malware with more than 107,000 samples that has been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/billions-android-devices-open-dirty-stream-attack\" rel=\"noopener\">targeting Android devices<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for more than two years is stealing SMS messages to acquire one-time passwords (OTPs) and other sensitive user data for further malicious activity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The malware, aptly dubbed &#8220;SMS Stealer&#8221; and which has a substantial cybercriminal infrastructure behind it, spreads via dynamically changing mobile apps distributed through Telegram messages or ads for legitimate apps, researchers from mobile security provider Zimperium zLabs have found.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since February 2022, the researchers have been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/legion-malware-marches-web-servers-steal-credentials-spam-mobile\" rel=\"noopener\">tracking the stealer<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which so far has been downloaded by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/-darcula-phishing-as-a-service-operation-bleeds-victims-worldwide\" rel=\"noopener\">victims in 113 countries,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/hackers-target-android-users-in-india-through-maas-campaign\" rel=\"noopener\">India<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and Russia topping the list, Zimperium researchers Aazim Bill SE Yaswant, Rajat Goyal, Vishnu Pratapagiri, and Gianluca Braga a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.zimperium.com\/blog\/unmasking-the-sms-stealer-targeting-several-countries-with-deceptive-apps\/\" rel=\"noopener\">outlined in blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> published on July 30. The campaign appears, in part, to be financially motivated by well-organized attackers who have at least 13 command-and-control (C2) servers and 2,600 Telegram bots at their disposal.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This ever-evolving campaign makes it particularly dangerous, as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/malicious-badpack-apk-files-android-malware\" rel=\"noopener\">it can evade<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> &#8220;traditional signature-based detection methods,&#8221; making it difficult for defenders to discover &#8220;without a sophisticated, on-device malware engine capable of detecting zero-day malware,&#8221; Nico Chiaraviglio, Zimperium chief scientist, says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;[The malware&#8217;s] ability to be dynamically generated and distribute unique malicious applications through multiple threat vectors to specific device users suggests a high level of sophistication and adaptability on the part of the threat actors,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, more than 99,000 of the malware samples analyzed by researchers were unknown and unavailable in generally available repositories, demonstrating that the campaign has remained largely undocumented by defenders over nearly two and a half years. Moreover, attackers are targeting more than 60 top-tier global brands in terms of the OTP messages the malware intercepts, with some brands having users in the hundreds of millions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For its part, a Google spokesperson tells Dark Reading, &#8220;Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services.&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/url.us.m.mimecastprotect.com\/s\/a3buCBB8n5tlyD54Mf60RKd?domain=support.google.com\" rel=\"noopener\">Google Play Protect<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Multiphase Campaign\">Multiphase Campaign<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The process of encountering the malware to infection and theft of SMS and other data takes place over several stages and is likely aimed at conducting further malicious activity with the stolen data, the researchers found.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;These stolen credentials serve as a springboard for further fraudulent activities, such as creating fake accounts on popular services to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/fishxproxy-phishing-kit-cybercriminals-success\" rel=\"noopener\">launch phishing campaigns<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> or social engineering attacks,&#8221; the researchers wrote in the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The campaign begins <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/remote-workforce\/snowblind-tampering-technique-may-drive-android-users-adrift\" rel=\"noopener\">when an Android user<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is tricked into sideloading a malicious application, either through a deceptive ad mimicking a legitimate app store, or through the usage of automated Telegram bots communicating directly with the target and using social engineering to get them to engage. Upon installation, the malicious application requests permission to read SMS messages, &#8220;a high-risk permission on Android that grants extensive access to sensitive personal data,&#8221; according to the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While legitimate applications may require SMS permissions for specific, well-defined functions, this particular app&#8217;s request is likely unauthorized and intended to exfiltrate the victim&#8217;s private text message communications,&#8221; the researchers wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once it gains permissions, the malware reaches out to find an address for a C2 server and then sets up a connection to transmit commands to be executed as well as stolen SMS messages. In the fifth and final phase, attackers transform the victim&#8217;s device into &#8220;a silent interceptor&#8221; on which the malware remains hidden and constantly monitors incoming SMS messages mainly for valuable OTPs for online account verification.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"&quot;Urgent Need&quot; for Better Mobile Defense\">&#8220;Urgent Need&#8221; for Better Mobile Defense<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While stealing SMS messages for financial gain is by no means a new threat, the dynamic and persistent approach of attackers in the campaign demonstrates &#8220;a refined and efficient attack method&#8221; that demands immediate response, Chiaravigli notes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, the growing proliferation of mobile malware, particularly pervasive and stealthy apps that can steal valuable OTPs, pose a significant threat to both individuals as well as enterprises, experts say. They not only invade users&#8217; privacy, but the sensitive data they access can provide a springboard for a range of malicious activity like credential theft, financial fraud, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/malwarebytes-cryptomining-surges-as-ransomware-declines\" rel=\"noopener\">ransomware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We have seen SMS redirection malware in the past, however, the ability of SMS Stealer to intercept OTPs, facilitate credential theft, and enable further malware infiltration poses severe risks,&#8221; notes Jason Soroko, senior vice president of product at Sectigo, a certificate life-cycle management provider.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This underscores the &#8220;urgent need&#8221; for organizations to adopt enhanced mobile security strategies that in particular stress the management of application permissions and continuous threat monitoring &#8220;to safeguard digital identities and enterprise integrity,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">New defense strategies should be multilayered and include a combination of advanced behavioral analysis, machine learning, and real-time threat intelligence, adds Stephen Kowski, field CTO at SlashNext Email Security+, saying, &#8220;Robust mobile threat defense solutions, proactive defense strategies, and continuous security updates play a pivotal role in identifying and neutralizing hidden malware.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/dynamically-evolving-sms-stealer-threatens-global-android-users\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A novel malware with more than 107,000 samples that has<\/p>\n","protected":false},"author":12,"featured_media":4725,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4724","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/dynamically-evolving-sms-stealer-threatens-global-android-users.png?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4724"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4724\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4725"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}