Automatically translated.View original post

BTMOB malware is deeply hidden on Android systems.

BTMOB malware found has the ability to hide deeply on Android systems.

According to a report by the website We Live Security, malware has been detected remotely controlling the victim's machine, or the new Remote Access Trojan, called BTMOB. The research team that detected the malware says that malware has a variety of capabilities, such as victim Sensitive Information, Screenshot and Recording, victim activity on board, and Remote Control. This malware is sold on the black market as MaaS or Malware-as-a-Service leased malware. With the APK Builder that allows users to easily create new payload files in a reliable application stain without the need to write a single line of code, all of which are sold through the developer's channel on the popular chat service Telegram. It is also promoted through social media like X and Instagram. It has a variety of prices, with a Lifetime price sold at $5,000 ($163,639.93).

In the area of malware fragmentation, it starts with the use of social engineering methods with phishing scams through fake websites that impersonate Streaming, Cryptocurrency Mining, and other online services. In the website, the scam invites the victim to download an APK file from a fake app store link or a digital library (Repo or Repository) to install on the victim's machine, which the campaign itself has been adapted to suit the region. Each target. After the installation is completed, the BTMOB malware will apply for various permissions on the victim's machine, including trying to access the Accessibility Mode. All of which malware can do without interaction with the victim, but it can be called a very malignant capability. For that outbreak, the malware is currently in a serious epidemic in Brazil, but the research team has warned that the malware may spread in Latin America and other areas in the world in the future.

For self-defense, the research team determined that users should download the application only from the official app store, as well as not trust any strange links, as well as to find a cybersecurity tool to install on their mobile phone so that they can stop it when misses occur.

# Trending # Lemon 8 Howtoo # lemon 8 diary # BTMOB # freedomhack

6/21 Edited to

... Read moreจากประสบการณ์ส่วนตัวและการติดตามข่าวสารเกี่ยวกับภัยคุกคามบนโทรศัพท์มือถือ Android พบว่า มัลแวร์ประเภท Remote Access Trojan หรือ RAT เช่น BTMOB นับเป็นภัยร้ายแรงที่ผู้ใช้ควรใส่ใจอย่างมาก เพราะมันสามารถลอบเข้าควบคุมเครื่องได้อย่างลึกและแอบบันทึกกิจกรรมต่าง ๆ เช่น การจับภาพหน้าจอ หรือแม้แต่การเปิดใช้งานโหมดช่วยเหลือผู้พิการ (Accessibility Mode) เพื่อเข้าถึงสิทธิ์การควบคุมเครื่องโดยไม่ถูกตรวจจับ สิ่งที่สร้างความน่ากลัวมากก็คือ BTMOB ถูกพัฒนาในรูปแบบ Malware-as-a-Service (MaaS) ที่ทำให้กลุ่มผู้ไม่หวังดีทั่วไปสามารถสร้างไฟล์ติดตั้ง APK ปลอมและแจกจ่ายได้ง่ายผ่านช่องทางโซเชียลมีเดีย เช่น Telegram, X และ Instagram โดยไม่จำเป็นต้องมีความรู้ทางโปรแกรมมิ่งมากนัก การหลอกลวงผ่านเว็บไซต์ปลอมที่แอบอ้างเป็นบริการสตรีมมิ่งหรือขุดเหรียญคริปโตจึงเป็นวิธีที่มักถูกใช้กระจายมัลแวร์นี้ การป้องกันที่ดีที่สุดที่ผมแนะนำจากประสบการณ์จริงคือ หลีกเลี่ยงการดาวน์โหลดแอปพลิเคชันจากแหล่งที่ไม่น่าเชื่อถือ โดยเฉพาะลิงก์ที่ส่งมาทางข้อความหรือช่องทางโซเชียลมีเดียที่ไม่คุ้นเคย ควรติดตั้งโปรแกรมรักษาความปลอดภัยที่มีคุณภาพบนมือถือเพื่อช่วยตรวจจับและป้องกันมัลแวร์เหล่านี้ นอกจากนั้นควรอัปเดตระบบปฏิบัติการและแอปพลิเคชันเสมอเพื่อแก้ไขช่องโหว่ที่อาจถูกใช้ประโยชน์ ทั้งนี้ ต้องตระหนักว่าการโจมตีแบบวิศวกรรมสังคม (Social Engineering) มีพัฒนาการและความซับซ้อนขึ้นเรื่อย ๆ ผู้ใช้ควรฝึกสังเกตสัญญาณผิดปกติ เช่น แอปที่ขอสิทธิ์เกินความจำเป็น หรือพฤติกรรมเครื่องที่ช้าและแปลกประหลาด เพื่อจะได้รีบดำเนินการตรวจสอบและแก้ไขได้ทันท่วงที การมีความรู้และความระมัดระวังจึงเป็นหัวใจสำคัญในการปกป้องข้อมูลส่วนบุคคลและความปลอดภัยบนอุปกรณ์ Android ในยุคนี้