Smishing Down Under

Stu Sjouwerman | Apr 17, 2019
talos-threat-insight

Banking malware is being installed on Android devices via malicious links in SMS messages, CRN reports. Cisco Talos discovered the malware being advertised on an exploit forum, and found that it was being used to target Australian financial organizations.

It contained 189 logos belonging to banks and cryptocurrency exchanges. When a victim clicks on a malicious link and installs the malware, it presents a realistic-looking overlay application imitating the login page of one of these organizations, depending on which apps are already installed on the phone. Users who fall for this trick will have their credentials stolen.

Since the malware has access to users’ text messages, it can bypass SMS-based two-factor authentication to break into victims’ bank accounts. It also accesses the victim’s address book and sends malicious links to several of their contacts from the victim’s phone. Additionally, the malware has sophisticated anti-analysis and persistence capabilities, making it harder to detect and remove.

While this particular campaign was focused on Australian companies, the researchers noted that the malware allows operators to filter organizations by country, and in this case, the “AU” code was selected. This indicates that the malware can easily target other nations as well.

This scam requires several actions on the part of the user in order to succeed. New-school security awareness training can teach your employees to avoid clicking on unsolicited links at all costs, even if they appear to come from a friend.

CRN has the story: https://www.crn.com.au/news/189-australian-financial-services-orgs-under-attack-by-sms-borne-malware-523635


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.