Moneycontrol PRO
HomeNewsTechnologyDarknet service allowing hackers to infect Android apps with malware

Darknet service allowing hackers to infect Android apps with malware

The malware targets both Windows and Android devices and has victims spread across Spain, Portugal and Canada

December 11, 2022 / 18:48 IST
Representative Image

Representative Image

Security researchers have unearthed a new malware campaign that targets both Windows and Android devices.

According to The Hacker News, this campaign entails the use of malware like ERMAC, a well-known Android banking trojan, or info-stealing malware such as Erbium, Aurora and Laplas.

The campaign has already resulted "in thousands of victims", says ThreatFabric, the cybersecurity firm that shared the report with The Hacker News.

"Erbium stealer successfully exfiltrated data from more than 1,300 victims."

ThreatFabric found that Zombinder dark web platform was used by hackers to bind malware to legitimate apps and has been used to target victims in Spain, Portugal, Canada and more.

What's worrying is how the malware was delivered to the victim's devices. ThreatFabric found a number of legitimate Android apps like Instagram that were infected with malware.

ThreatFabric said that bad actors "used a third-party service provided on darknet to “glue”, or bind, dropper capabilities to a legitimate application."

"After downloading the bound application, it will act as usual unless it shows a message stating that the app needs to be updated. At this point, if accepted by the victim, the seemingly legitimate application will install this update, which is nothing else than Ermac," ThreatFabric added.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Dec 11, 2022 06:48 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347