Breaking News

TerraMaster Black Friday & Cyber Monday 2025 Mega Sale Is Here HighPoint and ASK Corp Redefine 8K Post-Production with Verified 50.5GB/s Gen5 NVMe Storage at Inter BEE 2025 EDIFICE Launches the New ECB-S10 Series TCL and Call of Duty Unite to Elevate the Launch of Black Ops 7 With Next-Generation QD-Mini LED Immersion EnGenius Releases Broadband Outdoor EOC620 Mobile CPE for Transportation and Remote Operations

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Roaming Mantis Malware Infects Smartphones Through Wi-fi Routers

Roaming Mantis Malware Infects Smartphones Through Wi-fi Routers

Smartphones May 18,2018 0

Kaspersky Lab's experts claim that a malware dubbed 'Roaming Mantis' uses compromised routers to infect Android-based smartphones and tablets, redirect iOS devices to a phishing site, and runs a cryptomining script on desktops and laptops.

The malware was discovered last month and was initially considered to be a lcal threat, since it was attscking users from Japan, Korea, China, India, and Bangladesh. However, Roaming Mantis has since then learned to speak another two dozen languages and is rapidly spreading around the world.

The creators of Roaming Mantis have chosen a simple form of DNS hijacking: they hijack the settings of compromised routers forcing them to use their own rogue DNS servers. That means that whatever is typed in the browser address bar of a device connected to this router, the user is redirected to a malicious site. After the user is redirected to the malicious site, they are prompted to update the browser. This leads to the download of a malicious app named chrome.apk (there was another version as well, named facebook.apk).

The malware requests a whole host of permissions during the installation process, including rights to access accounts information, send/receive SMS, process voice calls, record audio, access files, display its own window on top of others, and so on. For a trusted application like Google Chrome, such a list doesn't seem too suspicious - if the user considers this 'browser update' legit, they are sure to grant permissions without even reading the list.

After the application is installed, the malware uses the right to access the list of accounts to find out which Google account is used on the device. Next, the user is shown a message (it appears on top of all other open windows, since the malware also requested permission for that) saying that something is wrong with their account and that they need to sign in again. A page then opens prompting the user to enter their name and date of birth.

It appears that this data, together with the SMS permissions that grant access to the one-time codes needed for two-factor authentication, is then used by the creators of Roaming Mantis to steal Google accounts.
Roaming Mantis: world tour, iOS debut, and mining

In the beginning, Roaming Mantis displayed messages in four languages: English, Korean, Chinese, and Japanese. But somewhere along the line its creators decided to expand out and teach their polyglot malware another two dozen languages:

Arabic
Armenian
Bulgarian
Bengali
Czech
Georgian
German
Hebrew
Hindi
Indonesian
Italian
Malay
Polish
Portuguese
Russian
Serbo-Croat
Spanish
Tagalog
Thai
Turkish
Ukrainian
Vietnamese

While they were at it, the creators also improved Roaming Mantis, teaching it to attack devices running iOS.

Accoding to Kaspersky, the cybercriminals do not confine themselves to stealing only Apple ID credentials; immediately after entering this data, the user is asked for a bank card number.

On desktop computers and laptops, Roaming Mantis runs the CoinHive mining script, which mines cryptocurrency straight into the pockets of the malware makers. The victim's computer processor is loaded to the max, forcing the system to slow down and consume vast amounts of power.

Security experts advise users to install antiviruses on all devices and regularly update all installed software on their devices. Om Android devices, users should disable installation of applications from unknown sources.

Tags: malware
Previous Post
Hisense Announces "Affordable" 80-inch Laser TV
Next Post
'Call Of Duty: Black Ops 4' Will Not Have a Single Player Campaign

Related Posts

  • Intel and Microsoft Convert Malware to Images to Spot Threads Faster

  • Malwarebytes Outlines Coronavirus Scams

  • Google's AI Tool Scans Billions of Gmail Attachments to Secure Inboxes

  • Pentagon, DHS And FBI Issued New Malware Warning For Windows Users

  • Lazarus Group Targets Linux With New Malware

  • Hackers Targeted Government Officials Using WhatsApp Malware

  • Malware Masked as Textbooks and Essays

  • Samsung Laptop Full of Notorious Malware Is On Sale For $1.2M

Latest News

TerraMaster Black Friday & Cyber Monday 2025 Mega Sale Is Here
Enterprise & IT

TerraMaster Black Friday & Cyber Monday 2025 Mega Sale Is Here

HighPoint and ASK Corp Redefine 8K Post-Production with Verified 50.5GB/s Gen5 NVMe Storage at Inter BEE 2025
Enterprise & IT

HighPoint and ASK Corp Redefine 8K Post-Production with Verified 50.5GB/s Gen5 NVMe Storage at Inter BEE 2025

EDIFICE Launches the New ECB-S10 Series
Consumer Electronics

EDIFICE Launches the New ECB-S10 Series

TCL and Call of Duty Unite to Elevate the Launch of Black Ops 7 With Next-Generation QD-Mini LED Immersion
Consumer Electronics

TCL and Call of Duty Unite to Elevate the Launch of Black Ops 7 With Next-Generation QD-Mini LED Immersion

EnGenius Releases Broadband Outdoor EOC620 Mobile CPE for Transportation and Remote Operations
Enterprise & IT

EnGenius Releases Broadband Outdoor EOC620 Mobile CPE for Transportation and Remote Operations

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed