NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / SMS theft alert: Android users under attack in 113 countries
    Summarize
    Next Article
    SMS theft alert: Android users under attack in 113 countries
    India and Russia are the most affected countries India and Russia are the most affected countries

    SMS theft alert: Android users under attack in 113 countries

    By Mudit Dube
    Jul 31, 2024
    03:07 pm

    What's the story

    A global SMS-stealing campaign has been detected, affecting Android devices across 113 countries.

    The operation employs thousands of Telegram bots to distribute malware that steals one-time two-factor authentication (2FA) passwords for more than 600 services.

    Researchers at Zimperium, a US-based mobile security company, have been monitoring this activity since February 2022 and have identified over 107,000 unique malware samples linked to the campaign.

    Malware spread

    Financial motives and distribution methods

    The primary motive behind this campaign is believed to be financial gain.

    The malware is disseminated either through malvertising or via Telegram bots that automate communication with potential victims.

    In the case of malvertising—the practice of incorporating malware in online advertisements—victims are directed to pages imitating Google Play, which display exaggerated download numbers to instill a false sense of trust.

    Bot strategy

    Telegram bots and personalized tracking

    On Telegram, the bots offer users pirated Android applications.

    Before providing the APK file, they request for the user's phone number which is then used to create a new APK for personalized tracking or future attacks.

    Zimperium reports that this operation involves 2,600 Telegram bots promoting various Android APKs, controlled by 13 command and control (C2) servers.

    Victim demographics

    India and Russia are the most affected countries

    The majority of victims from this campaign are based in India and Russia, with significant numbers also reported in Brazil, Mexico, and the US.

    The malware sends captured SMS messages to a specific API endpoint at 'fastsms.su,' a site that offers visitors the opportunity to buy access to "virtual" phone numbers in foreign countries for anonymization and authentication purposes on online platforms and services.

    Permission abuse

    Malware exploits Android SMS access permissions

    The malware exploits Android SMS access permissions to capture OTPs needed for account registrations and two-factor authentication.

    This could lead to unauthorized charges on victims' mobile accounts or their involvement in illegal activities traced back to their device and number.

    To prevent phone number misuse, users are advised not to download APK files from sources other than Google Play, deny risky permissions to apps with unrelated functionality, and ensure Play Protect is active on their device.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Android
    Telegram
    Malware
    Cybersecurity

    Latest

    Bangladesh Cricket Board pondering over Bangladesh's tour of Pakistan Bangladesh Cricket Board
    Why Virat Kohli's presence could lift India in England? Stats Virat Kohli
    Google Workspace accounts gain access to Gemini Live feature Google
    Adani Group deploys India's 1st hydrogen-powered truck in Chhattisgarh Adani Group

    Android

    YouTube unveils dedicated 'Your Podcasts' page for convenience of users YouTube
    Google Pixel 9 series to be launched on August 13 Android 15
    WhatsApp update for Android brings quickly reply to video messages WhatsApp
    Google introduces new features to enhance mobile search experience Google

    Telegram

    Telegram December update: No-SIM sign-up, upgraded topics, and more Latest Tech News
    Best WhatsApp features released in 2022: From Communities to Avatars  WhatsApp
    Telegram feature drop: Blurring option, drawing tools, zero storage options Android
    Twitter may auction usernames in a bid to boost revenue X

    Malware

    Hackers using fears over coronavirus to spread malware, steal data IBM
    'Cerberus' malware can steal 2FA codes from Google Authenticator X
    Hackers are infecting PCs, stealing passwords with coronavirus maps Cybersecurity
    COVID-19 scams are rising drastically: How to protect yourself Security

    Cybersecurity

    Proton Mail introduces 'Dark Web Monitoring' feature: How it works Technology
    Nothing confirms data breach of community profiles: Everything we know NOTHING
    Ransomware attack on UnitedHealth Group's subsidiary affects millions of Americans United States of America
    'Dirty Stream' attack: Tips to enhance security on Android devices Android
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025