Massive SMS stealer campaign infects Android devices in 113 countries

By Bill Toulas, Bleeping Computer

A malicious campaign targeting Android devices worldwide utilizes thousands of Telegram bots to infect devices with SMS-stealing malware and steal one-time 2FA passwords (OTPs) for over 600 services.

Zimperium researchers discovered the operation and have been tracking it since February 2022. They report finding at least 107,000 distinct malware samples associated with the campaign.

The cybercriminals are motivated by financial gain, most likely using infected devices as authentication and anonymization relays.

Telegram entrapment

The SMS stealer is distributed either through malvertising or Telegram bots that automate communications with the victim.

In the first case, victims are led to pages mimicking Google Play, reporting inflated download counts to add legitimacy and create a false sense of trust.

On Telegram, the bots promise to give the user a pirated application for the Android platform, asking for their phone number before they share the APK file.

The Telegram bot uses that number to generate a new APK, making personalized tracking or future attacks possible.


Telegram bot delivering the SMS stealer to a victim
Source: Zimperium

Zimperium says the operation uses 2,600 Telegram bots to promote various Android APKs, which are controlled by 13 command and control (C2) servers.

Most of the victims of this campaign are located in India and Russia, while Brazil, Mexico, and the United States also have significant victim counts.


Comments

Popular posts from this blog

Why remote desktop tools are facing an onslaught of cyber threats

Ransomware gang starts leaking alleged stolen Change Healthcare data

Notepad++ wants your help in "parasite website" shutdown