CONTACT US
info@bidaiondo.com

New phishing method tailored for Android and iOS users

ESET, a leading company in proactive threat detection, identified a phishing campaign targeting mobile users that targeted bank customers. This novel technique installs a phishing app from a third-party website without the user having to allow the installation of third-party apps, and affects both iOS and Android users. Most of the known cases so far have occurred in the Czech Republic, and apps targeted the Hungarian bank OTP Bank and the Georgian bank TBC Bank.

ESET's research team identified a series of phishing campaigns targeting mobile users that used three different URL delivery mechanisms: automated voice calls, SMS messages, and malvertising on social media.

The voice call delivery was done through an automated call that warned the user about an outdated banking app and asked them to select an option on the numeric keypad. After clicking the correct button, a phishing URL was sent via SMS.

The initial SMS approach was done by indiscriminately sending messages to Czech phone numbers. The message sent included a phishing link and a text to socially engineer victims into visiting the link.

The spread via malicious ads was done by registering ads on Meta platforms such as Instagram and Facebook. These ads included a call to action, such as a limited offer for users to “download an update below.” This technique allowed the threat actors to specify the target audience by age, gender, etc. The ads then appeared on the victims’ social media accounts.

After opening the URL delivered in the first stage, Android victims were presented with a high-quality phishing page that mimicked the official Google Play store page for the targeted banking app, or a copycat website for the app.

From there, victims are asked to install a “new version” of the banking app. Depending on the campaign, clicking the install/update button initiates the installation of a malicious app from the website, directly onto the victim’s phone, either in the form of a WebAPK (for Android users only), or as a Progressive Web App (PWA) for iOS and Android users. What’s notable about this instance is that it bypasses traditional browser warnings to “install unknown apps” – this is the default behavior of Chrome’s WebAPK technology, which is abused by attackers.

The process is a bit different for iOS users, as an animated pop-up tells victims how to add the phishing PWA to their home screen. The pop-up copies the look of native iOS prompts. In the end, iOS users are not warned about adding a potentially harmful app to their phone.

After installation, victims are asked to enter their online banking credentials to access their account via the new mobile banking app. All information provided is sent to the attackers’ C&C servers.

The malicious ads included a mix of the bank’s official mascot (blue chameleon), as well as bank logos and text promising a financial reward upon installing the app or warning users that a critical update had been released.

All stolen login information was logged via a backend server, which then sent the user’s entered banking login details to a Telegram group chat. HTTP calls to send messages to the threat actor’s group chat were made via the official Telegram API. According to ESET, this technique is not new and is used in several phishing kits.

“Since two drastically different C&C infrastructures were employed, we have determined that two different groups are responsible for spreading the phishing apps. More copycat apps will surely be created, as it is difficult to separate legitimate from phishing apps after installation. “All sensitive information found during our investigation was quickly forwarded to the affected banks for processing. We also coordinated the takedown of multiple phishing domains and C&C servers,” said Camilo Gutiérrez Amaya, Head of the ESET Latin America Research Laboratory.

https://newsinamerica.com/pdcc/gente/tecnologia/2024/nuevo-metodo-de-phishing-adaptado-a-usuarios-de-android-e-ios/

Last news

base_url:
host: www.bidaiondo.com
REQUEST_URI: /articles/new-phishing-method-tailored-for-android-and-ios-users
path: /news/kiabi-opens-its-marketplace-in-spain-giving-access-to-third-parties-and-incorporating-new-complementary-categories
Kiabi abre su marketplace en España, dando acceso a terceros e incorporando nuevas categorías complementarias
Kiabi ha anunciado el lanzamiento de su marketplace en España e Italia, un paso decisivo en su estrategia de transformación digital que abrirá su plataforma a nuevas marcas y comerciantes, a la vez que amplía las categor&i...
base_url:
host: www.bidaiondo.com
REQUEST_URI: /articles/new-phishing-method-tailored-for-android-and-ios-users
path: /noticias/shein-amplia-su-presencia-en-espana-abriendo-su-nuevo-hub-en-barcelona
Shein amplía su presencia en España abriendo su nuevo hub en Barcelona
Shein ha inaugurado su nuevo hub en Barcelona, incorporando la ciudad a su red internacional de más de 40 oficinas. Con esta apertura, la compañía “refuerza su enfoque local-global, integrando talento de la ciudad condal en...

online trading systems.

We show you the best way to market products and services online, through a professional service of installation, management and maintenance of your virtual store

We program to suit you

We help you achieve operational excellence in all your business processes, whether they are production, logistics, service or office processes. In addition, we assure you to maintain continuous improvement in your management.

Bidaiondo Articles

Beyond the hype: making AI the foundation of commerce

Retail is entering the age of agents. Increasingly, consumers are using artificial intelligence to discover products, compare options, and complete purchases on their behalf, across any platform where a conversation can take place: from search engines to chat interfaces. For retailers, the question is no longer whether to prepare for this scenario, but how to be present wherever their customers interact without losing control over the brand, the...

Ver más »

New voice effects for your Instagram audios

Instagram has launched a new feature that lets you add effects to the audio you send in direct messages. How to add voice effects to your audio in Instagram DMs Although these voice changes were already included in Edits, the platform's video editing app, it's not the same as having them there in your direct message conversations. When you want to send an audio message with effects: - Click on the microphone icon and record yo...

Ver más »