Massive SMS Theft Malware Hits Android Devices Across 113 Nations, Millions Affected

Since February 2022, a sophisticated Android malware campaign has emerged, targeting one-time passwords (OTPs) used in enterprise security.

zLabs researchers, while analyzing over 107,000 malware samples, observed that attackers continuously adapted their tactics to bypass security measures and infiltrate confidential corporate data. This long-term operation highlights the persistent battle between cyber defense systems and advanced mobile threats, exploiting the widespread use of OTPs for account protection.

Cybersecurity experts at Zimperium recently uncovered a new SMS stealer infecting millions of Android users across 113 countries.

This advanced malware attack employed various methods to compromise devices, spreading through deceptive ads and Telegram bots posing as legitimate services. Victims were tricked into downloading malicious APKs designed specifically for them based on their phone numbers, enabling the malware to access SMS and intercept OTPs.

Initially, the campaign’s infrastructure utilized Firebase as its command and control (C&C) server, later transitioning to GitHub repositories hosting obfuscated C&C URLs and malicious APKs. Most C&C servers relied on the Laravel framework. Once installed, the malware exfiltrated personal details, including SMS messages and device information, to servers controlled by the attackers, posing significant risks to both personal and corporate security.

This global Android malware campaign has reached an unprecedented scale, affecting 113 countries with Russia and India being the primary targets. Researchers identified over 107,000 distinct malware samples, 95% of which were previously unknown to standard repositories, showcasing the malware’s advanced evasion techniques.

The operation tracked OTPs across more than six hundred global brands, potentially impacting hundreds of millions of users. The infrastructure included 13 command and control servers and approximately 2,600 Telegram bots for malware distribution.

A related site, fastsms[.]su, revealed the financial motivation behind the campaign, selling stolen phone numbers and captured OTPs priced based on location and network operator.

The malware specifically targeted emails from a major cloud-based email and office suite provider, indicating a focus on high-value enterprise accounts.

The campaign’s scale and complexity underscore the evolving threat landscape in mobile security. The rise of sophisticated malware targeting SMS and OTPs signals significant risks for individuals and organizations, potentially leading to broader fraudulent activities.

This situation demands multi-layered security approaches, incorporating user training and advanced detection technologies to defend against unknown malware threats.

More Articles & Posts