[ad_1]
Two completely different Android banking Trojans, FluBot and Medusa, are counting on the identical supply automobile as a part of a simultaneous assault marketing campaign, in response to new analysis revealed by ThreatFabric.
The continuing side-by-side infections, facilitated via the identical smishing (SMS phishing) infrastructure, concerned the overlapping utilization of “app names, package deal names, and comparable icons,” the Dutch cellular safety agency stated.
Medusa, first found concentrating on Turkish monetary organizations in July 2020, has undergone a number of iterations, chief amongst which is the flexibility to abuse accessibility permissions in Android to siphon funds from banking apps to an account managed by the attacker.
“Medusa sports activities different harmful options like keylogging, accessibility occasion logging, and audio and video streaming — all these capabilities present actors with nearly full entry to [a] sufferer’s system,” the researchers stated.
The malware-ridden apps used along with FluBot masquerade as DHL and Flash Participant apps to contaminate the gadgets. As well as, current assaults involving Medusa have expanded their focus past Turkey to incorporate Canada and the U.S., with the operators sustaining a number of botnets for every of its campaigns.
FluBot (aka Cabassous), for its half, has acquired a novel improve of its personal: the flexibility to intercept and probably manipulate notifications from focused functions on a sufferer’s Android system by leveraging the direct reply motion, alongside auto-replying to messages from apps like WhatsApp to unfold phishing hyperlinks in a worm-like vogue.
“With this performance, this malware is ready to present [command-and-control server] equipped responses to notifications of focused functions on the sufferer’s system,” the researchers stated, including the performance “can be utilized by actors to signal fraudulent transactions on sufferer’s behalf.”
This isn’t the primary time Android malware has been discovered to propagate by creating auto-replies to messages in WhatsApp. Final yr, ESET and Verify Level Analysis uncovered rogue apps posing as Huawei Cell and Netflix that employed the identical modus operandi to carry out the wormable assaults.
“Increasingly more actors observe Cabassous’ success in distribution techniques, appropriating masquerading methods, and utilizing the identical distribution service,” the researchers stated. “On the identical time, Cabassous retains evolving, introducing new options and making one other step in direction of with the ability to carry out on-device fraud.”
[ad_2]


