Android malware RatMilad exposure: hidden in fake applications to spread, can extort or eavesdrop information
CTOnews.com, Oct. 9 (Xinhua)-- Mobile security company Zimperium has discovered a new Android malware, RatMilad, targeting mobile devices in the Middle East. According to the company, the malware was used for cyber espionage, extortion or eavesdropping on victims' conversations.
The malware is hidden behind the NumRent network and phone number spoofing applications. NumRent is distributed through links on social media and communications applications such as Telegram and WhatsApp. In order to convince people of the legitimacy of the app, the cyber criminals behind it also created a website to advertise the app.
Once installed, RatMilad hides behind the NumRent application and steals data, including the following:
Short message
Call log
Clipboard data
Device information (for example, model, brand, build number, Android version).
GPS location data
SIM card information
Contact information
List of installed applications
More importantly, CTOnews.com learned that RatMilad can delete data and upload files to its command and control server, modify application permissions, and use the device's microphone to record audio and eavesdrop conversations.
According to Zimperium, the cyber criminals behind RatMilad are randomly targeting rather than targeting certain individuals and businesses.
To protect Android devices from RatMilad and other malware, avoid downloading apps from third-party app stores. In addition, malware needs to be scanned frequently and the permissions of the application reviewed.