Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le janvier 18, 2018, 10:00:58

Titre: [Trend]GhostTeam Adware can Steal Facebook Credentials
Posté par: igor51 le janvier 18, 2018, 10:00:58
GhostTeam Adware can Steal Facebook Credentials

We uncovered a total of 53 apps on Google Play that can steal Facebook accounts and surreptitiously push ads. Many of these apps, which were published as early as April 2017, seemed to have been put out on Google Play in a wave. Detected by Trend Micro as ANDROIDOS_GHOSTTEAM, many of the samples we analyzed are in Vietnamese, including their descriptions on Google Play.


Their command-and-control (C&C) server points to mspace[.]com[.]vn. This, along with the considerable use of Vietnamese language, may indicate that the apps were from Vietnam. For instance, GhostTeam’s configurations are in English and Vietnamese. English will be the default language if the malware detects the geolocation to be outside Vietnam.


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


GhostTeam Adware can Steal Facebook Credentials


Source: GhostTeam Adware can Steal Facebook Credentials (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/6ldP2ZxUcgE/)