The new malware on Android "RedHook" is insidious.
The new malware on Android "RedHook" is insidious.
The level may clear your money.
According to a report by the Android Authority website, a research team from Group-IB, an expert company developing cybersecurity solutions, has detected a malware type that remotely controls the victim's machine, or a RAT (Remote Access Trojan) called RedHook, where hackers send download links via text messages, email, social media, or even by telling them links via phone calls, claiming to be from a well-known organization to deceive the victim. Hackers try to convince the victim to download the APK installation file through such a link that the page looks like the official app store. Google Play Store, but literally it's not.
After the victim has downloaded and installed the file successfully, the application will deceive the Permission to access the disabled user or Accessibility Mode, claiming that there is a need for the application operation. After the victim has completed the authorization, the malware will activate the Wireless ADB feature through Developer Mode to access Shell Access (UID 2000). This results in the malware being able to access the victim's machine completely and capture important information through Keystroke, streaming. The screen returns to the hacker (Screen Streaming) and controls the lock of the screen. All the stolen data leads to the theft of money in the bank account from the bank application installed on the machine.
The research team also revealed that the malware that the team detected was a new version developed from the original version that was detected last year by another cybersecurity firm, Cyble. This version is so much more malicious that removing the malware from the machine is so difficult that it is almost impossible to use techniques such as WakeLock to trick the machine into running all the time, Kill Android, the process of malware, and sometimes malware can pretend that the screen is not locked by booking a small 1x1 px screen that is so smooth. There is also a process resurrection mechanism that has two processes. When one of them is shut down, the other process will immediately resurrect the one that has been shut down.
This malware is in Vietnam and is already spreading to Indonesia.
# Trending # lemon 8 diary # Android # RedHook # freedomhack
จากประสบการณ์จริงของผู้ใช้งาน Android หลายท่านที่เคยเจอกับมัลแวร์ที่อาศัยช่องทางหลอกดาวน์โหลดไฟล์แอป APK นอก Google Play Store แล้วพบว่า RedHook มีความอันตรายระดับสูง เพราะนอกจากจะควบคุมเครื่องแบบเต็มสูบแล้ว ยังใช้เทคนิค WakeLock ทำให้โทรศัพท์ทำงานอยู่ตลอดเวลา และมีกลไกให้ Process ของมัลแวร์ฟื้นคืนชีพเองหลังถูกปิด ทำให้กำจัดได้ยากมาก การที่ RedHook ถูกออกแบบให้ขอสิทธิ์ Accessibility ซึ่งเป็นสิทธิ์ที่แอปใช้เข้าถึงระบบลึก ๆ เช่น ควบคุมหน้าจอและรับข้อมูลการพิมพ์บนเครื่องนั้น ถือว่าเป็นหนึ่งในรูปแบบมัลแวร์ที่อันตรายที่สุดตัวหนึ่ง ด้วยเหตุนี้จึงควรหลีกเลี่ยงการติดตั้งแอปจากแหล่งที่ไม่แน่ใจ รวมถึงไม่ควรคลิกลิงก์ที่ได้รับจากข้อความหรืออีเมลที่ไม่ชัวร์ จากคำแนะนำของนักวิจัยด้านความปลอดภัย การป้องกันที่ดีที่สุดคือการอัปเดตระบบ Android เป็นเวอร์ชันล่าสุดอยู่เสมอ รวมทั้งใช้แอปแอนตี้มัลแวร์ที่เชื่อถือได้ และหมั่นตรวจสอบสิทธิ์แอปที่ติดตั้งบนเครื่อง หากพบแอปที่ขอสิทธิ์ Accessibility โดยไม่รู้จักควรยกเลิกทันที สำหรับผู้ที่คิดว่าตัวเองอาจติดมัลแวร์ RedHook สามารถลองรีเซ็ตเครื่องเป็นค่าโรงงาน (Factory Reset) เพื่อจัดการกับมัลแวร์ที่ฝังลึก ถึงแม้จะเสียข้อมูลบางส่วนแต่ก็ปลอดภัยกว่าเสี่ยงถูกขโมยข้อมูลสำคัญหรือเงินในบัญชี สุดท้าย การอัพเดตความรู้และรับข่าวสารเกี่ยวกับมัลแวร์ รวมถึงวิธีป้องกันเป็นสิ่งจำเป็นในยุคที่ภัยคุกคามไซเบอร์พัฒนาเร็วขึ้นทุกวัน เพื่อให้ผู้ใช้งานปลอดภัยและมั่นใจในข้อมูลส่วนตัวของตนเองมากที่สุด
