SMiShing Scheme Uses Fake Android Banking App to Steal Identifiers and SMS Data
#1
Quote:A fake Android banking app found on Google Play was exfiltrating device identifiers, SMS messages, and phone numbers to its command-and-control (C&C) server, as discovered by Trend Micro's Echo Duan.

Once installed and launched on an Android device, the fake mobile token Movil Secure app hides by removing its icon from the screen and will collect a number of device identifiers (i.e., device ID, OS version, and Country Code) which it will then send to its C&C server and a phone number hardcoded in the device identifier collection function.

In addition, the fake banking app also exfiltrates phone numbers and SMS messages, with a possible goal of collecting all the data and using it in a later SMiShing campaign which might have already been started seeing that there are reports of people who installed this app and have been scammed afterward.

Source: https://news.softpedia.com/news/smishing...3694.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AdGuard Browser Extension 5.2.77
More information a...harlan4096 — 07:00
Microsoft Edge Version 140.0.3485.81
ersion 140.0.3485....harlan4096 — 06:55
Vivaldi 7.6 Build 3797.55
Vivaldi 7.6 Build ...harlan4096 — 06:54
Virtual-machine escape – in a Spectre v2...
A fresh research p...harlan4096 — 06:53
Windows 11 is getting a video wallpaper ...
Microsoft is testi...harlan4096 — 06:51

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (38)eqiduseb
avatar (40)maskbSleew

[-]
Online Staff
There are no staff members currently online.

>