Malware

Millions of Android devices pre-infected with malware

0

A large cybercrime enterprise named as “Lemon Group” has reportedly pre-installed malware known as ‘Guerilla’ on almost 9 million Android-based smartphones, watches, TVs, and TV boxes.

The threat actors use Guerilla malware to load additional payloads, intercept one-time passwords from SMS, set up a reverse proxy from the infected device, hijack WhatsApp sessions, and more.

The analysts at Trend Micro discovered the huge criminal enterprise and presented details about it at the recent BlackHat Asia conference. According to their reports some of the attackers’ infrastructure overlaps with the Triada trojan operation from 2016.

Triada was a banking trojan found pre-installed in 42 Android smartphone models from low-cost Chinese brands that sell their products globally.

The researchers first exposed the Lemon Group in February 2022, and soon after, the group allegedly rebranded under the name “Durian Cloud SMS.” However, the attackers’ infrastructure and tactics remained the same.

Trend Micro has not explained on how Lemon Group infects devices with the malicious firmware containing Guerilla but clarified that the devices its analysts examined had been re-flashed with new ROMs.

The infections are globally spread across in over 180 countries, with over 50 brands of mobile devices compromised by the malware strain.

The criminal group are now branching out to other Android-based IoT devices such as Smart TVs, Android TV boxes, entertainment systems, and even children’s watches.

The infection turns the devices into mobile proxies, tools for stealing and selling SMS messages, social media and online messaging accounts and monetization via advertisements and click fraud.

Unauthorized firmware modifications could have been done by methods such as supply chain attacks, compromised third-party software, a compromised firmware update process, or enlisting insiders on the product manufacturing or distribution chain.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Teen hacker charged over DraftKings credential stuffing case

Previous article

UK Man jailed for 13 Years for multi-Million-pound fraud operation

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *