Automatically translated.View original post

Beware! Manic malware can sneak data on Android

Beware! Manic malware can sneak data on Android to hackers, even with offline phones.

According to a report by the website Security Affairs, a hybrid of banking Trojan and spyware focused on tackling users of a new Android operating system called Manic by the Mobile Threat Intelligence Team from ThreatFabric, an online fraud management specialist. The research team has identified the current malware in Ukraine through impersonating bank applications, state applications, Kryptokerrenzi applications, and the applications of various financial institutions in Russia and Europe, among others. The malware will be available. Monitor more than 169 applications in the state applications category, scriptokerrency applications such as Exchange and Crypto Wallet apps, and 2FA or 2-Factors Authentication apps, etc.

In the field of malware, after the victim has become addicted to a fake application with malware insertion into the machine, the malware will request access to the Accessibility Mode and Notification System, and then use the Accessibility Mode ability to capture data with Keylogging, such as screen unlock codes, email login codes, SMS or Short Message Service codes, Seed Phrases, long messages, etc., which can capture the PIN code of this malware by using Accessibility Mode traps from the real Numeric Keypad instead of the overlay screen. There is also an implementation of the autoEnterPin function used to enter the PIN code to unlock the screen without the victim knowing the automatic sample.

All captured data is logged as a Log with complete data, such as text, app name, package name, timestamp, and source of input, such as Manual Input or Autofill, etc. To export these data can be done even if the machine is not connected to the Internet with a Store-and-Forward Relay mechanism. At this point, malware-infected machines detect malware-infected machines through the Wi- channel. Fi Direct, Bluetooth RFCOMM, or BLE GATT then forwards the data to them so that the receiving machine forwards the stolen data back to the control server (C2 or Command and Control).

In addition to that, the malware also provides a tool called WebRTC to allow hackers to access and control the victim's machine remotely easily. Not only did the malware update during the month of July add a lot of malware to this malware - a stronger Anti-Analysis system, an In-Memory DEX Loading system, a fake screen use system to steal the PIN code, unlock the machine before reaching the real unlock screen (Lock-Secret Phishing), and also removing itself from the screen for activating applications (App Launcher). Hide yourself more closely from the eyes of your victims, too.

# Trending # lemon 8 diary # manic # freedomhack # Android

4 days agoEdited to

... Read moreจากประสบการณ์การใช้งานโทรศัพท์ Android ที่ผ่านมา การระมัดระวังการดาวน์โหลดแอปฯ จากแหล่งที่ไม่น่าเชื่อถือเป็นสิ่งสำคัญมาก โดยเฉพาะอย่างยิ่งเมื่อมัลแวร์ Manic นี้สามารถแฝงตัวเองในรูปแบบแอปพลิเคชันธนาคาร, แอปสำหรับคริปโต หรือแม้กระทั่งแอปยืนยันตัวตนสองชั้น ที่มักถูกใช้งานบ่อยๆ การที่มัลแวร์สามารถใช้โหมด Accessibility เพื่อติดตามการพิมพ์และการเข้าถึงข้อมูลสำคัญอย่าง PIN หรือ Seed Phrases เป็นสิ่งที่ควรระวังอย่างยิ่ง เพราะมันไม่ได้เพียงแค่ขโมยข้อมูลผ่านอินเทอร์เน็ตเท่านั้น แต่ยังสามารถส่งข้อมูลผ่านเครือข่ายเครื่องติดมัลแวร์ด้วยกัน ผ่าน Wi-Fi Direct หรือ Bluetooth แบบเข้ารหัส ซึ่งหมายความว่าถึงแม้มือถือจะไม่ได้ออนไลน์ ก็ยังเสี่ยงถูกขโมยข้อมูลอยู่ดี ผมเคยพบว่าการตั้งค่าความปลอดภัยบนโทรศัพท์ Android หลาย ๆ รุ่นจะรวมถึงการจำกัดการเข้าถึงโหมด Accessibility สำหรับแอปที่ไม่น่าเชื่อถือ วิธีหนึ่งที่ช่วยลดความเสี่ยงคือการตรวจสอบสิทธิ์การเข้าถึงของแอปต่าง ๆ อย่างสม่ำเสมอ รวมถึงการไม่เปิดใช้งานแอปที่ไม่น่าเชื่อถือหรือไม่ได้ดาวน์โหลดจาก Google Play Store อย่างเป็นทางการ นอกจากนี้ ผู้ใช้งานควรติดตั้งแอปแอนตี้มัลแวร์ที่มีความน่าเชื่อถือและได้รับการอัปเดตอยู่เสมอเพื่อช่วยตรวจจับภัยคุกคาม และระมัดระวังการคลิกลิงก์หรืออีเมลที่น่าสงสัย เพราะหลายครั้งมัลแวร์ Manic จะถูกปลอมตัวมากับลิงก์หรือแอปเช่นนี้ โดยสรุป แม้ว่ามัลแวร์ Manic จะเป็นภัยคุกคามที่อันตรายและมีเทคนิคขั้นสูง ผู้ใช้เองสามารถลดความเสี่ยงได้ด้วยการใส่ใจความปลอดภัยบนมือถือ รู้เท่าทันสิทธิ์การเข้าถึงของแอป และรักษาความปลอดภัยด้านข้อมูลส่วนตัวอย่างเข้มงวด