NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / Iranian hackers develop malware to steal 2FA codes
    Next Article
    Iranian hackers develop malware to steal 2FA codes

    Iranian hackers develop malware to steal 2FA codes

    By Shubham Sharma
    Sep 21, 2020
    05:46 pm

    What's the story

    Often, security experts recommend two-factor authentication (2FA) as a way to add an extra layer of security to your online accounts and services such as Facebook and Instagram.

    Now, to break past this wall, a group of Iranian hackers has come up with Android malware that can steal 2FA codes, without your knowledge.

    Here are more details.

    Hackers

    Rampant Kitten's surveillance campaign

    As reported by Check Point researchers, hackers from Iranian group Rampant Kitten are using this malware as part of a set of tools being deployed for an ongoing surveillance campaign.

    They have been active for years and are targeting Iranian minorities, anti-regime organizations, and resistance movements such as Association of Families of Camp Ashraf and Liberty Residents, Azerbaijan National Resistance Organization, and Baloch people.

    Working

    How it works?

    The malware in question comes as a backdoor in innocuous-looking applications and performs a range of intrusive tasks like stealing the targets' contacts, recording their voice, or showing them phishing pages designed to steal confidential login credentials.

    But, among all this, the researchers also discovered that the malware can intercept and forward incoming two-factor authentication codes to the attackers in real-time.

    Impact

    Codes for several services appear to be affected

    The report from the security firm notes that the backdoor seems to be detecting and stealing 2FA codes of several internet and social services, including those operated by Google and Telegram.

    For Google's case, the malware reportedly looked for messages containing the "G-" string, the prefix the company uses for its 2FA codes, while for other services it automatically forwarded all incoming messages.

    Loophole

    Other 2FA options do not appear to be impacted

    Even though the malware has all the elements to let an attacker break into a person's account, it has a major loophole.

    Specifically, the malware is only aimed at SMS-based 2FA codes, which experts have frequently flagged as the least secure option, as messages can be intercepted.

    If you are using some other 2FA option, your account will not be affected by it.

    App

    Only one app detected with the malware so far

    As of now, the researchers have flagged just a single application with this malware - a program designed to let Persian speakers get their driver's license in Sweden.

    However, going by the reputation of Rampant Kitten, the team believes that there might be more apps with this malicious backdoor, particularly those aimed at Iranians opposing the Tehran regime.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Security
    Malware
    Google
    Two-Factor Authentication

    Latest

    Who is India's most successful Test captain on England soil? Indian Cricket Team
    No duty cuts on British wine in India-UK trade deal United Kingdom
    Sneh Rana records career-best WODI returns against SL; Amanjot shines Indian Women's Cricket Team
    TVS's cheapest e-scooter to be launched soon: What we know TVS Motor Company

    Security

    20 popular VPN, ad-blocking apps caught spying on users iOS
    Hackers are exploiting an 'unpatched' vulnerability in Windows 10 Microsoft
    Microsoft halting less important Windows updates: Here's why Microsoft
    Marriott suffers data breach, over 5 million guest records stolen Cybersecurity

    Malware

    New malware can steal information from Chrome, Firefox browsers Microsoft Word
    Symantec discovers 45 malicious apps on Google Play Store South Africa
    Russian hackers infect over 500,000 routers worldwide with malware Russia News
    VPNFilter router malware: Capabilities, risks, and reach United States of America

    Google

    Why are Apple, Google and Epic Games fighting? Apple
    OnePlus TV Y Series' OTA update brings nifty improvements OnePlus
    #OutageAlert: Gmail, Drive, Docs, and other services are down [Fixed] X
    LG K31, with Helio P22 chipset and dual cameras, launched LG

    Two-Factor Authentication

    Two-factor authentication: Protect your online accounts against hackers X
    Now, enable two-factor authentication on Twitter without linking your number X
    Facebook will not use two-factor phone numbers for suggesting friends Facebook
    Now, use your iPhone as a Google security key iOS
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025