Automatically translated.View original post

RAT malware on Android running Watchdog Services

RAT malware was found on Android, running Watchdog Services and Boot Receivers to evade being shut down at reboot.

According to a report by the website Cyber Security News, a new RAT type of malware called Octagon has been detected in Bahrain. It is disguised as a state-owned Alert Service, which snatches the rhythm of the Middle East crisis, tricking victims into phishing websites to download such (fake) applications that are not available on the official Android app store, such as the Google Play Store. The fake pages, if opened via mobile, are so similar to the Google Play Store that many victims have lost their way of downloading such illegal applications to install them. Ultimately addicted to malware.

For the process of embedding malware into the machine, it will start with an installation file called BH-Alert.apk. Before installation, seven steps will be granted to access the victim's system. The first application at the outpost will hide the malware code in an encryption file called ZfChs.ttf. The file will be decrypted on the machine at the time of use, making the malware scanner unable to see the code. The first application will then install the OctagonPanel application and create a code file as the machine runs time by the Service of this malware. It works in the background. In this part, the surveillance service or the Watchdog Services will monitor each other and immediately reopen the malware if it is stopped. This prevents the first layer of downtime. If it is rebooted, it cannot stop the malware. Boot Receivers will also reopen the malware immediately. In addition, the malware has created a fake Android account called OctagonPanel and rescheduled the sync task every 30 minutes, which is called Persistence. Wisely.

After the malware has fully embedded and handled the above matters, the malware will request the right to use the Disabled User Support Mode or Accessibility Mode to steal screen unlock numbers, passwords, and other sensitive information that the user has typed in, allowing hackers to take over the victim's machine and complete the use of the Virtual Private Network. The foreground deceives the victim as a use for data security. In fact, the use of the Tunnel also allows hackers to easily capture sensitive information by the application. Others that the malware does not require are packaged on the exclusion list, causing the data of those applications to run through normal channels until no fault is noticed.

Not only that, malware can also intercept short messages (SMS or Short Message Service), contacts, call logs, settings, and can secretly record screenshots. Overlay Attacks can also be used to overlay the screen of applications that need to store data. It allows the theft of the victim's code in another way.

# Trending # lemon 8 diary # Lemon 8 Howtoo # rat # freedomhack

9/5 Edited to

... Read moreจากประสบการณ์การใช้งานสมาร์ทโฟน Android หลายปี ผมเคยได้รับข้อมูลเกี่ยวกับมัลแวร์ RAT ที่พยายามฝังตัวในเครื่องผ่านแอปปลอมที่ไม่ได้มาจาก Google Play Store ซึ่งมักจะหลอกล่อให้ผู้ใช้ติดตั้งด้วยวิธีการที่ทำให้ดูน่าเชื่อถือ เช่น ปลอมเป็นบริการสำคัญของรัฐบาลหรือแอปความปลอดภัย เช่นเดียวกับมัลแวร์ Octagon ที่กำลังระบาดในบาห์เรนและใช้เทคนิค Watchdog Services ในการตรวจสอบกันและกันเพื่อป้องกันไม่ให้ถูกบังคับปิด สิ่งที่น่ากังวลมากคือการที่ Octagon ใช้ Boot Receivers เพื่อเริ่มทำงานทุกครั้งที่รีบูตเครื่อง และยังมีการสร้างบัญชี Android ปลอมเพื่อซิงค์ข้อมูลตลอดเวลา ซึ่งแสดงถึงการวางแผนอย่างรัดกุมเพื่อคงทนบนอุปกรณ์ ทำให้ผู้ใช้แทบไม่รู้ตัวเลยว่ากำลังถูกสอดแนมโดยมัลแวร์ ที่ผมเจอทั่วไปอีกอย่างคือแอปเหล่านี้จะขอสิทธิ์เข้าถึงระบบในระดับสูง เช่น Accessibility Mode ซึ่งโดยปกติช่วยให้คนพิการใช้โทรศัพท์ได้ง่ายขึ้น แต่กลับถูกใช้ในการขโมยรหัสผ่าน หมายเลขปลดล็อก และข้อมูลการใช้งานอื่น ๆ ที่พิมพ์ลงบนเครื่อง การสื่อสารผ่าน VPN ปลอมก็สร้างความมั่นใจผิด ๆ ว่าข้อมูลจะปลอดภัย ทั้งที่จริงแล้วข้อมูลถูกดักจับไปโดยแฮกเกอร์ ดังนั้นผมแนะนำให้ผู้ใช้ Android ระมัดระวังมากขึ้น โดยติดตั้งแอปเฉพาะจาก Play Store เท่านั้น และตรวจสอบสิทธิ์ที่แอปขอใช้งานอย่างละเอียด ถ้ายังจำเป็นต้องใช้แอปจากแหล่งอื่น ควรสแกนหาไวรัสและตรวจสอบความน่าเชื่อถือก่อนทุกครั้ง นอกจากนี้ควรตั้งค่าความปลอดภัยในเครื่องอย่างเหมาะสม เช่น เปิดการอัปเดตแพตช์ความปลอดภัยล่าสุด และติดตั้งแอปแอนตี้ไวรัส เพื่อเสริมเกราะป้องกันไม่ให้ตกเป็นเหยื่อของมัลแวร์เหล่านี้ได้ง่าย ๆ สุดท้าย ผมคิดว่าความรู้และความตื่นตัวของผู้ใช้งานคือสิ่งที่สำคัญที่สุดที่จะช่วยรับมือกับภัยคุกคามไซเบอร์ที่ซับซ้อนและแฝงตัวอยู่ในแอปพลิเคชันเหล่านี้ได้จริงๆ