Newsletter
REAL HACKER NEWS
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
REAL HACKER NEWS
No Result
View All Result
Home APPLICATIONS

FakeCalls Vishing Malware Targets South Korean Users via Popular Financial Apps

Real Hacker Staff by Real Hacker Staff
March 17, 2023
in APPLICATIONS
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

Apple Music has an amazing feature that no-one ever talks about

March 24, 2023

The Apple Watch Ultra finally has some competition from an unlikely source

March 24, 2023


Mar 17, 2023Ravie LakshmananMobile Security / Scam Alert

An Android voice phishing (aka vishing) malware campaign known as FakeCalls has reared its head once again to target South Korean users under the guise of over 20 popular financial apps.

“FakeCalls malware possesses the functionality of a Swiss army knife, able not only to conduct its primary aim but also to extract private data from the victim’s device,” cybersecurity firm Check Point said.

FakeCalls was previously documented by Kaspersky in April 2022, describing the malware’s capabilities to imitate phone conversations with a bank customer support agent.

In the observed attacks, users who install the rogue banking app are enticed into calling the financial institution by offering a fake low-interest loan.

At the point where the phone call actually happens, a pre-recorded audio with instructions from the real bank is played. At the same time, malware also conceals the phone number with the bank’s real number to give the impression that a conversation is happening with an actual bank employee on the other end.

The ultimate goal of the campaign to get the victim’s credit card information, which the threat actors claim is required to qualify for the non-existent loan.

The malicious app also requests for intrusive permissions so as to harvest sensitive data, including live audio and video streams, from the compromised device, which are then exfiltrated to a remote server.

The latest FakeCalls samples further implement various techniques to stay under the radar. One of the methods involves adding a large number of files inside nested directories to the APK’s asset folder, causing the length of the file name and path to breach the 300-character limit.

“The malware developers took special care with the technical aspects of their creation as well as implementing several unique and effective anti-analysis techniques,” Check Point said. “In addition, they devised mechanisms for disguised resolution of the command-and-control servers behind the operations.”

FakeCalls Vishing Malware

While the attack exclusively focuses on South Korea, the cybersecurity company has warned that the same tactics can be repurposed to target other regions across the world.

The findings also come as Cyble shed light on two Android banking trojans dubbed Nexus and GoatRAT that can harvest valuable data and carry out financial fraud.

Nexus, a rebranded version of SOVA, also incorporates a ransomware module that encrypts the stored files and can abuse Android’s accessibility services to extract seed phrases from cryptocurrency wallets.

WEBINAR

Discover the Hidden Dangers of Third-Party SaaS Apps

Are you aware of the risks associated with third-party app access to your company’s SaaS apps? Join our webinar to learn about the types of permissions being granted and how to minimize risk.

RESERVE YOUR SEAT

In contrast, GoatRAT is designed to target Brazilian banks and joins the likes of BrasDex and PixPirate to commit fraudulent money transfer over the PIX payments platform while displaying a fake overlay window to hide the activity.

The development is part of a growing trend where threat actors have unleashed increasingly sophisticated banking malware to automate the whole process of unauthorized money transfers on infected devices.

Cybersecurity company Kaspersky said it detected 196,476 new mobile banking trojans and 10,543 new mobile ransomware trojans in 2022, with China, Syria, Iran, Yemen, and Iraq emerging as the top countries attacked by mobile malware, including adware.

Spain, Saudi Arabia, Australia, Turkey, China, Switzerland, Japan, Colombia, Italy, and India lead the list of top countries infected by mobile financial threats.

“Despite the decline in overall malware installers, the continued growth of mobile banking Trojans is a clear indication that cybercriminals are focusing on financial gain,” Kaspersky researcher Tatyana Shishkova said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: AppsFakeCallsFinancialKoreanMalwarePopularSouthTargetsUsersVishing
Share76Tweet47

Related Posts

Apple Music has an amazing feature that no-one ever talks about

by Real Hacker Staff
March 24, 2023
0

The recent Spotify redesign didn’t fill me with confidence on the platform’s direction for the future, so it was high...

The Apple Watch Ultra finally has some competition from an unlikely source

by Real Hacker Staff
March 24, 2023
0

The Apple Watch Ultra is the undisputed king of wearables right now. It's big and beautiful and it's a dive...

Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data

by Real Hacker Staff
March 24, 2023
0

Mar 24, 2023Ravie LakshmananDevSecOps / Software Security A malicious Python package on the Python Package Index (PyPI) repository has been...

Inside the High Risk of 3rd-Party SaaS Apps

by Real Hacker Staff
March 24, 2023
0

Mar 24, 2023The Hacker NewsSaaS Security / Webinar Any app that can improve business operations is quickly added to the...

Twitter is about to take everyone’s blue checkmarks away, unless you pay for one

by Real Hacker Staff
March 24, 2023
0

Twitter is about to pull the plug on what is likely its most controversial change yet, as the company moves...

Load More
  • Trending
  • Comments
  • Latest

eSIMs Will Transform the Way You Think About Mobile Data and Security

March 7, 2023

XMOS Launches XVF3800 High-Performance Voice Processor for Enterprise and Consumer Voice Conferencing Platforms

March 7, 2023

Sennheiser Starts Shipping EW-DX Digital Wireless Microphone Series

November 22, 2022

Chinese Hackers Using Russo-Ukrainian War Decoys to Target APAC and European Entities

December 7, 2022

Hello world!

0
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

RISC-Y Business: Arm wants to charge dramatically more for chip licenses

March 24, 2023

French parliament votes for biometric surveillance at Paris Olympics

March 24, 2023

Where Is Xur Today? (March 24-28) – Destiny 2 Exotic Items And Xur Location Guide

March 24, 2023

Apple Music has an amazing feature that no-one ever talks about

March 24, 2023

Recent News

RISC-Y Business: Arm wants to charge dramatically more for chip licenses

March 24, 2023

French parliament votes for biometric surveillance at Paris Olympics

March 24, 2023

Categories

  • APPLICATIONS
  • AUDIO
  • CAMERA
  • COMPUTERS
  • GAMING
  • LAPTOP
  • REVIEWS
  • SECURITY
  • SMARTPHONES
  • Uncategorized
REAL HACKER NEWS

We bring you the best news on Internet new gadgets hacking and technology from around the world

  • Contact
  • Cookie Privacy Policy
  • Terms and Conditions
  • Privacy Policy
  • Disclaimer
  • DMCA

© 2003 Real Hacker News

No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO

© 2003 Real Hacker News

Go to mobile version