Auteur Sujet: [FireEye]Android Users Beware -- ‘Mandiant’-Branded Malware Identified  (Lu 2590 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Android Users Beware -- ‘Mandiant’-Branded Malware Identified


 

FireEye Labs recently identified malware for Android devices that
    masquerades as a Mandiant product. The malware can lock Android
    devices and displays a lock screen that uses the Mandiant brand.


   

To a victim in the United States, this lock screen may appear
  as:


          style="border: 2.0px solid black;" alt="Figure 1"
      src="https://www.fireeye.com/content/dam/legacy/ammo/Figure-16.png"
      width="536" height="819" />

To try to make the lock message
    more convincing, the criminals can use a different header image
    depending on the victim's country:

    class="size-full wp-image-5708 " style="border: 2.0px solid black;"
    title="Banner displayed to victims in the US"
    alt="Banner displayed to victims in the US"
    src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-the-US.jpg"
    width="1000" height="175" />Banner displayed to victims in the
    US    style="border: 2.0px solid black;"
    alt="Banner displayed to victims in Australia"
    src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-Australia.jpg"
    width="1000" height="175" />Banner displayed to victims in
    Australia    style="border: 2.0px solid black;"
    alt="Banner displayed to victims in Ireland"
    src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-Ireland.jpg"
    width="1000" height="175" />Banner displayed to victims in
    Ireland    style="border: 2.0px solid black;"
    alt="Banner displayed to victims in Poland"
    src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-Poland.jpg"
    width="1000" height="175" />Banner displayed to victims in
    Poland    style="border: 2.0px solid black;"
    alt="Banner displayed to victims in France"
    src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-France.jpg"
    width="1000" height="175" />Banner displayed to victims in
    France

The Android malware is typically delivered by tricking the
    victim into installing it after visiting a malicious website. Once
    installed, it will run every time the device boots and displays the
    lock screen. The malware can communicate with several command and
    control servers using the following domains:

-
  police-strong-mobile[.]com

- mobile-policeblock[.]com

-
  police-secure-mobile[.]com

- police-scan-mobile[.]com

-
  police-mobile-stop[.]com

- police-guard-mobile[.]com

Our
    research indicates police-strong-mobile[.]com is actively in use,
    and has been online since March 29, 2014.

The apps themselves
    are well obfuscated-the method names inside the app are written in
    non-meaningful strings. The methods the app calls are constructed
    using a 5-byte XOR key dynamically. We have also noticed different
    XOR keys used for every different decoding instance. The app also
    blocks access to images, and it forces the user to pay a fee to
    access the contents.

This isn't the first time that we've
    seen cybercriminals trading on Mandiant's brand. Last year, Mandiant
    identified PC malware that was locking users' computers and
    displaying content saying the system was locked due to criminal
    activity. As       href="https://www.mandiant.com/blog/malware-mandiants/"
      target="_blank">we indicated last year, this is part of a scam
    designed to extort money from victims.

We recommend victims
    of this malware report the incident to the       href="https://www.ic3.gov/default.aspx" target="_blank">Internet
      Crime Center.


Source: Android Users Beware -- ‘Mandiant’-Branded Malware Identified

Tags: