SMiShing Scheme Uses Fake Android Banking App to Steal Identifiers and SMS Data
#1
Quote:A fake Android banking app found on Google Play was exfiltrating device identifiers, SMS messages, and phone numbers to its command-and-control (C&C) server, as discovered by Trend Micro's Echo Duan.

Once installed and launched on an Android device, the fake mobile token Movil Secure app hides by removing its icon from the screen and will collect a number of device identifiers (i.e., device ID, OS version, and Country Code) which it will then send to its C&C server and a phone number hardcoded in the device identifier collection function.

In addition, the fake banking app also exfiltrates phone numbers and SMS messages, with a possible goal of collecting all the data and using it in a later SMiShing campaign which might have already been started seeing that there are reports of people who installed this app and have been scammed afterward.

Source: https://news.softpedia.com/news/smishing...3694.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.2.0 / 19.2.3 Update
Changes in 19.2.3 ...harlan4096 — 07:10
Google Chrome 140.0.7339.207 / 140.0.733...
Google Chrome 140....harlan4096 — 07:08
hunderbird 143.0.1
Thunderbird 143.0....harlan4096 — 07:06
Firefox add-on developers may roll back ...
For many users, a ...harlan4096 — 07:05
Microsoft silently introduces Windows AI...
Microsoft has quie...harlan4096 — 07:04

[-]
Birthdays
Today's Birthdays
avatar (40)maskbSleew
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (38)eqiduseb

[-]
Online Staff
There are no staff members currently online.

>