<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ESET research team &#8211; Bitfinance</title>
	<atom:link href="https://bitfinance.news/en/etiqueta/eset-research-team/feed/" rel="self" type="application/rss+xml" />
	<link>https://bitfinance.news</link>
	<description>Fintech &#38; new economy info</description>
	<lastBuildDate>Mon, 26 Aug 2024 14:15:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bitfinance.news/wp-content/uploads/2025/01/favicon-64.png</url>
	<title>ESET research team &#8211; Bitfinance</title>
	<link>https://bitfinance.news</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Malicious banking applications: New phishing against Android and iOS users</title>
		<link>https://bitfinance.news/en/malicious-banking-applications-new-phishing-against-android-and-ios-users/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Mon, 26 Aug 2024 12:00:55 +0000</pubDate>
				<category><![CDATA[Financial security]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[Android and iOS users]]></category>
		<category><![CDATA[automated voice calls]]></category>
		<category><![CDATA[Camilo Gutiérrez Amaya]]></category>
		<category><![CDATA[criminal technique]]></category>
		<category><![CDATA[cybercrime attacks]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[ESET research team]]></category>
		<category><![CDATA[malicious ads]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[Research Laboratory]]></category>
		<category><![CDATA[SMS messages]]></category>
		<category><![CDATA[Warning]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=108610</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1331" height="861" src="https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET analizó campañas de phishing que combinan técnicas tradicionales con el uso de tecnologías de iOS y Android para instalar aplicaciones vulnerantes sin el consentimiento del usuario" decoding="async" fetchpriority="high" srcset="https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS.jpg 1331w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-300x194.jpg 300w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-1024x662.jpg 1024w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-768x497.jpg 768w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-210x136.jpg 210w" sizes="(max-width: 1331px) 100vw, 1331px" /></div><p>ESET, a leading company in proactive threat detection, identified a phishing campaign aimed at mobile users that targeted bank customers. This novel criminal technique installs a phishing application from a third-party website without the user having to allow the installation of applications, it affects both iOS and Android users. Most of the cases known at [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/malicious-banking-applications-new-phishing-against-android-and-ios-users/">Malicious banking applications: New phishing against Android and iOS users</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1331" height="861" src="https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET analizó campañas de phishing que combinan técnicas tradicionales con el uso de tecnologías de iOS y Android para instalar aplicaciones vulnerantes sin el consentimiento del usuario" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS.jpg 1331w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-300x194.jpg 300w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-1024x662.jpg 1024w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-768x497.jpg 768w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-210x136.jpg 210w" sizes="(max-width: 1331px) 100vw, 1331px" /></div><p style="text-align: justify;"><strong><a href="https://www.eset.com/latam/" target="_blank" rel="noopener">ESET</a>,</strong> a leading company in proactive threat detection, identified a phishing campaign aimed at mobile users that targeted bank customers. This novel <strong>criminal technique</strong> installs a phishing application from a third-party website without the user having to allow the installation of applications, it affects both iOS and Android users. Most of the cases known at the moment have occurred in the Czech Republic, and applications were directed to the Hungarian bank OTP Bank and the Georgian bank TBC Bank.</p>
<p style="text-align: justify;"><strong>The ESET research team</strong> identified a series of phishing campaigns targeting mobile users that used three different <strong>URL delivery mechanisms: automated voice calls, SMS messages, and social media malvertising.</strong></p>
<p style="text-align: justify;"><strong>Voice call</strong> delivery was done via an automated call that warned the user about an outdated banking application and asked them to select an option on the keypad. After pressing the correct button, a phishing URL was sent via SMS.</p>
<p style="text-align: justify;">The initial approach by <strong>SMS</strong> was carried out by indiscriminately sending messages to Czech telephone numbers. The message sent included a phishing link and a text for victims to perform social engineering and visit the link.</p>
<p style="text-align: justify;">The spread through<strong> malicious ads</strong> was done by registering ads on Meta platforms such as Instagram and Facebook. These ads included a call to action, such as a limited offer for users to “download an update below.” This technique allowed threat actors to specify the target audience by age, gender, etc. The ads then appeared on the victims&#8217; social networks.</p>
<p style="text-align: justify;">After opening the URL delivered in the first stage, Android victims were faced with a <strong>high-quality phishing page that imitated the official Google Play Store page</strong> for the targeted banking app, or an imitation website of the app.</p>
<figure id="attachment_108607" aria-describedby="caption-attachment-108607" style="width: 899px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-108607 size-full" src="https://bitfinance.news/wp-content/uploads/2024/08/1.png" alt="PWA phishing flow" width="899" height="311" srcset="https://bitfinance.news/wp-content/uploads/2024/08/1.png 899w, https://bitfinance.news/wp-content/uploads/2024/08/1-300x104.png 300w, https://bitfinance.news/wp-content/uploads/2024/08/1-768x266.png 768w" sizes="(max-width: 899px) 100vw, 899px" /><figcaption id="caption-attachment-108607" class="wp-caption-text">PWA phishing flow</figcaption></figure>
<p>&nbsp;</p>
<p style="text-align: justify;">From there, victims are asked to install a “new version” of the banking app. Depending on the campaign, clicking the install/update button initiates the installation of a malicious application from the website, directly on the victim&#8217;s phone, either in the form of a <a href="https://web.dev/articles/webapks" target="_blank" rel="noopener">WebAPK</a> (Android users only), or as a Progressive Web App (PWA)<strong> for iOS and Android users.</strong> The highlight of this instance is that it bypasses traditional browser warnings to &#8220;install unknown apps&#8221;: this is the default behavior of <strong>Chrome&#8217;s WebAPK technology, which is abused by attackers.</strong></p>
<p style="text-align: justify;">The process is a little different for iOS users, as an animated pop-up tells victims how to add the phishing PWA to their home screen. The popup copies the look of native iOS messages. In the<strong> end, iOS users are not warned about adding a potentially harmful app to their phone.</strong></p>
<p style="text-align: justify;">Upon installation, victims are asked to enter their internet banking credentials to access their account through the new mobile banking application. All information provided is sent to the<strong> attackers&#8217; C&amp;C servers.</strong></p>
<p style="text-align: justify;">The malicious ads included a mashup of the bank&#8217;s official mascot (blue chameleon), as well as bank logos and text promising a financial reward for installing the app or warning users that a critical update had been released.</p>
<figure id="attachment_108608" aria-describedby="caption-attachment-108608" style="width: 750px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-108608 " src="https://bitfinance.news/wp-content/uploads/2024/08/2.png" alt="Example of a malicious ad used in these campaigns" width="750" height="694" srcset="https://bitfinance.news/wp-content/uploads/2024/08/2.png 485w, https://bitfinance.news/wp-content/uploads/2024/08/2-300x278.png 300w" sizes="(max-width: 750px) 100vw, 750px" /><figcaption id="caption-attachment-108608" class="wp-caption-text">Example of a malicious ad used in these campaigns</figcaption></figure>
<p>&nbsp;</p>
<p style="text-align: justify;">All stolen login information was recorded through a backend server, which then sent the banking login details entered by the user to a Telegram group chat. HTTP calls to send messages to the threat actor&#8217;s group chat were made through the official Telegram API. <strong>As mentioned by ESET: this technique is not new and is used in several phishing kits.</strong></p>
<h4 style="text-align: left;"><span style="color: #008000;">Warning</span></h4>
<p style="text-align: justify;"><em>“Because two drastically different C&amp;C infrastructures were used, we have determined that two different groups are responsible for the spread of phishing applications. More imitation apps will surely be created, since after installation it is difficult to separate legitimate apps from phishing ones. All sensitive information found during our investigation was quickly sent to the affected banks for processing. We also coordinate the dismantling of multiple phishing domains and C&amp;C servers,” </em>says <strong>Camilo Gutiérrez Amaya</strong>, Head of the<strong> ESET Latin America Research Laboratory.</strong></p>
<p style="text-align: justify;">Contact coordinates with ESET in Venezuela: <a href="https://www.eset.com/ve/" target="_blank" rel="noopener">https://www.eset.com/ve/</a>. Also, their social networks: Instagram <a href="https://www.instagram.com/esetla/" target="_blank" rel="noopener">@esetla</a>) and Facebook: (<a href="https://www.facebook.com/ESETLA" target="_blank" rel="noopener">ESET</a>).</p>
<p style="text-align: left;"><em>With information and reference image provided by ESET and Comstat Rowland</em></p>
<p style="text-align: left;">Visit our news channel on <a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener">Google News</a> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on <a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener">Twitter</a> and <a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener">Instagram</a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/malicious-banking-applications-new-phishing-against-android-and-ios-users/">Malicious banking applications: New phishing against Android and iOS users</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
