Kaspersky Lab researchers have discovered a new Android malware distributed through a domain name system (DNS) hijacking technique and targeting smartphones, mostly in Asia. The campaign, dubbed Roaming Mantis remains highly active and is designed to steal user information including credentials and to provide attackers with full control over the compromised Android device. Between February and April 2018, researchers detected the malware in over 150 user networks, mainly in South Korea, Bangladesh, and Japan, but there are likely to be many more victims. Researchers believe a cybercriminal group looking for financial gain is behind the operation.

 

According to Vitaly Kamluk, Director of the Global Research Analysis Team (GReAT) – APAC, “The story was recently reported in the Japanese media, but once we did a little more research, we found that the threat does not originate there. In fact, we found a number of clues that the attacker behind this threat speaks either Chinese or Korean. Further, the majority of victims were not located in Japan either. Roaming Mantis seems to be focusing mainly on Korea and Japan appears to have been a kind of collateral damage.

 

Kaspersky Lab’s findings indicate that the attackers behind the malware seek out vulnerable routers for compromise, and distribute the malware through a simple yet very effective trick of hijacking the DNS settings of those infected routers. The method of router compromise remains unknown. Once the DNS is successfully hijacked, any attempt by users to access any website leads them to a genuine-looking URL with forged content coming from the attackers’ server. This includes the request: “To better experience the browsing, update to the latest chrome version.” Clicking on the link initiates the installation of a Trojanized application named either ‘facebook.apk’ or ‘chrome.apk’, which contains the attackers’ Android backdoor.

 

The Roaming Mantis malware checks to see if the device is rooted and requests permission to be notified of any communications or browsing activity undertaken by the user. It is also capable of collecting a wide range of data, including credentials for two-factor authentication. Researchers found that some of the malware code includes references to mobile banking and game application IDs popular in South Korea. Taken together, these indicators suggest a possible financial motive behind this campaign.

 

While Kaspersky Lab’s detection data uncovered around 150 targets, further analysis also revealed thousands of connections hitting the attackers’ command & control (C2) servers on a daily basis, pointing to a far larger scale of attack.

 

The design of Roaming Mantis’ malware shows it is intended for wider distribution across Asia. Among other things, it supports four languages: Korean, simplified Chinese, Japanese, and English. However, the artefacts gathered suggest the threat actors behind this attack are familiar mostly with Korean and simplified Chinese.

 

Roaming Mantis is an active and rapidly changing threat. This is why we are publishing our findings now, rather than waiting until we have all the answers. There appears to be considerable motivation behind these attacks, and we need to raise awareness so that people and organizations can better recognize the threat. The use of infected routers and hijacked DNS highlights the need for robust device protection and the use of secure connections,” says Suguru Ishimaru, Security Researcher at Kaspersky Lab Japan.

 

Kaspersky Lab products detect this threat as ‘Trojan-Banker.AndroidOS.Wroba

In order to protect your internet connection from this infection, Kaspersky Lab recommends the following:

  • Refer to your router’s user manual to verify that your DNS settings haven’t been tampered with, or contact your ISP for support.
  • Change the default login and password for the admin web interface of the router.
  • Never install router firmware from third party sources. Avoid using third-party repositories for your Android devices.
  • Regularly update your router’s firmware from the official source.

RECOMMENDED ARTICLE FOR TECHWORLD


 
Printers, eSport and Cryptocurrencies: New Kaspersky Lab DDoS Intelligence Quarterly Report Combines Them All
Techworld Date Posted: 25 July 2018 4:27 PM | 218 Views
Kaspersky Lab has published its report on botnet-assisted DDoS attacks for the second quarter of 2018. Over the last three months, the company’s experts have observed cybercriminals recall old vulnerabilities, make use of cameras.... See More
 
Printers, eSport and Cryptocurrencies: New Kaspersky Lab DDoS Intelligence Quarterly Report Combines Them All
Techworld Date Posted: 4:27 PM | 218 Views
Kaspersky Lab has published its report on botnet-assisted DDoS attacks for the second quarter of 2018. Over the last three months, the company’s experts have observed cybercriminals recall old vulnerabilities, make use of cameras...See More

 
Introducing New Nokia Smartphones: Delivering Pioneering Experiences across the Range and True Innovation in Imaging
Techworld Date Posted: 27 February 2019 4:12 PM | 115 Views
HMD Global, the home of Nokia phones, today announced four new Android smartphones, including the world’s first smartphone with a unique five camera array, the Nokia 9 PureView. With a dedication to delivering quality.... See More
 
Introducing New Nokia Smartphones: Delivering Pioneering Experiences across the Range and True Innovation in Imaging
Techworld Date Posted: 4:12 PM | 115 Views
HMD Global, the home of Nokia phones, today announced four new Android smartphones, including the world’s first smartphone with a unique five camera array, the Nokia 9 PureView. With a dedication to delivering quality...See More

 
Acer Philippines Maintains No. 1 Spot in the PC Market for 10 Years
Techworld Date Posted: 4 March 2019 3:43 PM | 86 Views
The results are in. The growth of the country’s Philippine Personal Computer (PC) market is the fastest in the ASEAN region. Acer leads the Philippine PC market in all circumstances for 10 years straight.... See More
 
Acer Philippines Maintains No. 1 Spot in the PC Market for 10 Years
Techworld Date Posted: 3:43 PM | 86 Views
The results are in. The growth of the country’s Philippine Personal Computer (PC) market is the fastest in the ASEAN region. Acer leads the Philippine PC market in all circumstances for 10 years straight...See More

 
Transcend Releases Lightning-fast PCIe Solid-state Drive for Mac Computers
Techworld Date Posted: 29 August 2017 3:50 PM | 248 Views
Transcend Information Inc., a leading manufacturer of storage and multimedia products, is proud to announce the release of the JetDrive 820 PCI Express (PCIe) Gen 3.0 solid-state drive (SSD) for Mac computers. The JetDrive.... See More
 
Transcend Releases Lightning-fast PCIe Solid-state Drive for Mac Computers
Techworld Date Posted: 3:50 PM | 248 Views
Transcend Information Inc., a leading manufacturer of storage and multimedia products, is proud to announce the release of the JetDrive 820 PCI Express (PCIe) Gen 3.0 solid-state drive (SSD) for Mac computers. The JetDrive...See More

 
HyperX Now the Official Gaming Headset Partner of the Dallas Mavericks and the Future Dallas NBA 2K League Team
Techworld Date Posted: 7 December 2017 3:19 PM | 320 Views
HyperX®, the gaming division of Kingston Technology, announced the official gaming headset sponsorship of the Dallas Mavericks and the future Dallas NBA 2K League team. . See More
 
HyperX Now the Official Gaming Headset Partner of the Dallas Mavericks and the Future Dallas NBA 2K League Team
Techworld Date Posted: 3:19 PM | 320 Views
HyperX®, the gaming division of Kingston Technology, announced the official gaming headset sponsorship of the Dallas Mavericks and the future Dallas NBA 2K League team. See More

 
Power Mac Center Pioneers iPhone Display Repairs in PH
Techworld Date Posted: 23 July 2018 2:46 PM | 593 Views
Power Mac Center’s Apple Authorized Service Provider is now offering replacement repair services for damaged iPhone display screens. It is the first Service Center in the country to do so. Coverage includes cracked screens.... See More
 
Power Mac Center Pioneers iPhone Display Repairs in PH
Techworld Date Posted: 2:46 PM | 593 Views
Power Mac Center’s Apple Authorized Service Provider is now offering replacement repair services for damaged iPhone display screens. It is the first Service Center in the country to do so. Coverage includes cracked screens...See More

 
DJI Develops Option for Pilots to Fly Without Internet Data Transfer
Techworld Date Posted: 16 August 2017 3:00 PM | 296 Views
DJI, the world's leader in civilian drones and aerial imaging technology, is developing a new local data mode that stops internet traffic to and from its flight control apps, in order to provide enhanced.... See More
 
DJI Develops Option for Pilots to Fly Without Internet Data Transfer
Techworld Date Posted: 3:00 PM | 296 Views
DJI, the world's leader in civilian drones and aerial imaging technology, is developing a new local data mode that stops internet traffic to and from its flight control apps, in order to provide enhanced...See More

 
Tier One Closes a 7-Figure Foreign Investment to Strengthen Its Presence in South East Asia
Techworld Date Posted: 14 September 2018 3:14 PM | 894 Views
The past few years have seen a widespread boom in the confidence that companies have for esports. Even owners of NBA franchises see the potential that the esports industry has, and have invested heavily.... See More
 
Tier One Closes a 7-Figure Foreign Investment to Strengthen Its Presence in South East Asia
Techworld Date Posted: 3:14 PM | 894 Views
The past few years have seen a widespread boom in the confidence that companies have for esports. Even owners of NBA franchises see the potential that the esports industry has, and have invested heavily...See More

 
Lenovo’s Gift Guide for the Holiday Season
Techworld Date Posted: 22 December 2018 2:56 PM | 132 Views
Looking for the perfect gadgets for yourself or to give away to your families and friends this Christmas? Lenovo, the world’s leading PC and smart devices developer has compiled the best tech gifts that.... See More
 
Lenovo’s Gift Guide for the Holiday Season
Techworld Date Posted: 2:56 PM | 132 Views
Looking for the perfect gadgets for yourself or to give away to your families and friends this Christmas? Lenovo, the world’s leading PC and smart devices developer has compiled the best tech gifts that...See More

 
Sprout Solutions Supports Local Startup Community in PH through a Series of Free Learning Sessions
Techworld Date Posted: 16 December 2017 5:16 PM | 366 Views
Sprout Solutions, the fastest-growing Filipino tech startup providing a complete suite of HR software tools specifically made for the Philippine business environment, gives back by supporting the country’s startup community through its series of.... See More
 
Sprout Solutions Supports Local Startup Community in PH through a Series of Free Learning Sessions
Techworld Date Posted: 5:16 PM | 366 Views
Sprout Solutions, the fastest-growing Filipino tech startup providing a complete suite of HR software tools specifically made for the Philippine business environment, gives back by supporting the country’s startup community through its series of...See More


Power by

Download Free AZ | Free Wordpress Themes