Saturday, September 5, 2026
HomeCyber Security'Roaming Mantis' Android Malware Concentrating on Europeans by way of Smishing Campaigns

‘Roaming Mantis’ Android Malware Concentrating on Europeans by way of Smishing Campaigns

[ad_1]

A financially motivated marketing campaign that targets Android units and spreads cell malware by way of SMS phishing strategies since a minimum of 2018 has unfold its tentacles to strike victims situated in France and Germany for the primary time.

Dubbed Roaming Mantis, the most recent spate of actions noticed in 2021 contain sending pretend shipping-related texts containing a URL to a touchdown web page from the place Android customers are contaminated with a banking trojan often known as Wroba whereas iPhone customers are redirected to a phishing web page that masquerades because the official Apple web site.

Automatic GitHub Backups

The highest affected international locations, primarily based on telemetry information gathered by Kaspersky between July 2021 and January 2022, are France, Japan, India, China, Germany, and Korea.

Additionally tracked below the names MoqHao and XLoader (to not be confused with the info-stealer malware of the identical identify concentrating on Home windows and macOS), the group’s exercise has continued to increase geographically even because the operators broadened their assault strategies to mine cryptocurrency from Apple units and evade detection.

'Roaming Mantis' Android Malware

The first purpose of the marketing campaign is to deploy Wroba, which capabilities each as a adware and banking malware, with capabilities to switch reputable apps with malicious variations and steal credentials related to victims’ on-line financial institution accounts.

Prevent Data Breaches

Additional evaluation of the malware artifacts has revealed the shift in programming language from Java to Kotlin and the addition of two new backdoor instructions that permit Wroba to exfiltrate galleries and photographs from contaminated units.

“One attainable state of affairs is that the criminals steal particulars from things like driver’s licenses, medical insurance playing cards or financial institution playing cards, to enroll in contracts with QR code cost providers or cell cost providers,” the researchers mentioned. “The criminals are additionally in a position to make use of stolen photographs to get cash in different methods, corresponding to blackmail or sextortion.”



[ad_2]

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments