Rewterz Threat Alert – TA2101 Plays Government Imposter to Distribute Ransomware
November 15, 2019Rewterz Threat Alert – More Than a Dozen Obfuscated APT33 Botnets Used for Extreme Narrow Targeting
November 15, 2019Rewterz Threat Alert – TA2101 Plays Government Imposter to Distribute Ransomware
November 15, 2019Rewterz Threat Alert – More Than a Dozen Obfuscated APT33 Botnets Used for Extreme Narrow Targeting
November 15, 2019Severity
High
Analysis Summary
IMobile-VERIFY is Android malware that Sucuri detected being used as part of an income tax themed phishing scheme believed to be targeting India. Potential victims would need to be lured to a webpage where the malicious app resides and is forcibly downloaded onto the victim device using JavaScript. The victim would need to have allowed installation of apps from third-party sites and agree to allowing the app permissions, including making it the default app for SMS messages. The app is used in an attempt to have the user provide banking details. If the victim has allowed the app to become the default SMS app, it could intercept any SMS messages including those such as 2FA messages used in banking transactions, potentially allowing the attackers controlling the app to steal funds from bank accounts.
Impact
Financial loss
Indicators of Compromise
MD5
6271c05865bfb38f29b1b5bf425ed7e8
SH256
8da0016f9da5d595521c4a07e1d00b58dacaede1a86219eef54a76ae612647b7
SHA1
c6f59e5e95986ba23fe3f6c18d42743761b2e837
URL
http[:]//stylecollections[.]ru/admin/controller/extension/manz[.]php
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on the links/attachments sent by unknown senders.