New Android threat campaign targeting Facebook credentials
Android threat campaign "Schoolyard Bully Trojan" discovered by Zimperium, a leading mobile security company. threat actor using educational android application to target Facebook credentials of user. according to researcher this campaign is active since 2018 and infected over 300000 victims. application looks like real application which offer wide range of books and note and other stuff which helps students and capable to steal the Facebook credentials and uploaded to Firebase command and control center. to minimize the detection from antivirus and real time protection "Schoolyard Bully Trojan" use native libraries .
all the application which discovered by researcher is removed from play store but still they are available by third party stores. the infection process start under the chat option and used java-script injection to harvest the Facebook credentials including user's phone number, email address, and password and send it to Firebase C&C server.
Subscribe to:
Post Comments (Atom)
Fake Job Interviews, Real Threats: The Rise of OtterCookie Malware
North Korean Hackers Unleash OtterCookie Malware in Sophisticated Job Scam North Korean cyber operatives have unveiled a new weapon in the...
-
DigiCert's Revocation of 83,000 Certificates: A Critical Security Move DigiCert has begun the process of revoking over 83,000 SSL/TLS ...
-
The notorious Craxs Rat malware has recently unleashed its latest version, Update V5, introducing a range of new features and enhancements....
-
AWS Seizes Domains Used by Russian Threat Group APT29 in Credential-Stealing Campaign Amazon Web Services (AWS) has disrupted a phishing o...
No comments:
Post a Comment