Vietnam.vn - Nền tảng quảng bá Việt Nam

Users are at risk of having their OTP codes stolen on Android phones

Công LuậnCông Luận03/08/2024


According to a report from security company Zimperium, this campaign has been detected and monitored since February 2022. To date, at least 107,000 related malware samples have been identified.

The malware mainly targets Android devices, with the aim of stealing OTP codes, a type of one-time password, commonly used for two-factor authentication during logins or online transactions.

The campaign used more than 2,600 Telegram bots to spread the malware, controlled by 13 Command & Control (C&C) servers. The victims of this campaign spanned 113 countries, but were most concentrated in India, Russia, Brazil, Mexico, and the United States.

Users are at risk of being hacked on Android phones, image 1

Android users face the risk of having their OTP codes stolen

The malware is distributed in two main ways. Victims can be tricked into visiting fake websites that look like Google Play. Or victims can be lured into downloading pirated APK apps through Telegram bots. To download the app, users must provide their phone number, which the malware then uses to create a new APK file, allowing the attacker to track or carry out further attacks.

When a user unknowingly grants SMS access to a malware-infected app, the malware will be able to read SMS messages, including OTP codes sent to the phone. This not only allows attackers to steal sensitive information, but also puts the victim at risk of account abuse and even financial fraud.

Once the OTP code is stolen, the attacker can easily access the victim's bank accounts, e-wallets, or other online services, causing serious financial consequences. Not only that, some victims may also be involved in illegal activities without even knowing it.

Zimperium also found that the malware transmitted stolen SMS messages to an API endpoint at 'fastsms.su', a website that sells access to virtual phone numbers in foreign countries. These phone numbers can be used to anonymize online transactions, making them more difficult to trace.

To protect themselves from the risk of attack, Android users are advised to:

Don't download APK files from sources outside of Google Play: These files may contain malicious code that can easily steal your information.

Do not grant SMS access to unknown apps: This will limit the risk of malware being able to read messages containing your OTP code.

Enable Play Protect: This is a Google Play security feature that scans and detects malicious apps on your device.



Source: https://www.congluan.vn/nguoi-dung-co-nguy-co-bi-danh-cap-ma-otp-tren-dien-thoai-android-post306111.html

Comment (0)

No data
No data

Same tag

Same category

Visit Lo Dieu fishing village in Gia Lai to see fishermen 'drawing' clover on the sea
Locksmith turns beer cans into vibrant Mid-Autumn lanterns
Spend millions to learn flower arrangement, find bonding experiences during Mid-Autumn Festival
There is a hill of purple Sim flowers in the sky of Son La

Same author

Heritage

;

Figure

;

Enterprise

;

No videos available

News

;

Political System

;

Destination

;

Product

;