Rechercher dans ce blog

Wednesday, December 16, 2020

New iOS, Android spyware targeting users in extortion campaign - AppleInsider

ios.indah.link

A new mobile spyware is targeting both iOS and Android users in what appears to be an extortion campaign tied to illicit websites.

The malware, dubbed "Goontact," can steal data like contacts, SMS text messages, photos, and location information from an iPhone or Android. It's currently appears limited to Chinese-speaking countries, Korea, and Japan.

According to the Lookout security researchers who discovered it, "Goontact" targets users who visit illicit sites, typically those offering escort services. The ultimate goal seems to be extortion or blackmail tied to users visiting or soliciting services from those sites.

The scam starts when a user is lured to a website hosting the spyware. Although they appear to be talking to an escort, scam victims are actually communicating with "Goontact" operators, who convince them that they need to side-load an app on their iOS or Android devices.

Although the spyware and similar scams are not uncommon, the portion of the campaign targeting iOS users has been previously unreported, Lookout said. The iOS version of "Goontact" primarily steals a user's phone number and contact list, though newer versions can also display a message to the victim.

Like other side-loaded iOS malware threats, "Goontact" operators use an Apple enterprise developer certificate to distribute the spyware outside of the App Store. The certificates used in the Spyware campaign all reference what appear to be legitimate companies, including credit unions and railroad corporations.

It isn't clear if those legitimate companies have been compromised, or if the bad actors masqueraded as representatives of them to obtain the certificates.

During the course of Lookout's research, the team noticed multiple certificates being revoked. Once they were, new identities appeared on distribution sites, indicating that "Goontact" operators had no trouble obtaining new certificates.

Who's at risk, and how to protect yourself

"Goontact" doesn't appear to have spread beyond China, Japan, Korea, Thailand, and Vietnam yet, though there's a chance that it or a similar spyware strain could.

The spyware operators rely on social engineering to convince users to side-load the malicious apps onto devices. Because of that, if you never attempt to side-load anything, you won't be at risk.

As far as general best practices, it's always recommended to only download apps through the official App Store from developers that you trust, and to keep the software on your iPhone, iPad, or other device up to date.

The Link Lonk


December 16, 2020 at 09:49PM
https://ift.tt/3np18Nj

New iOS, Android spyware targeting users in extortion campaign - AppleInsider

https://ift.tt/2ZaIe2Q
iOS

No comments:

Post a Comment

Featured Post

Microsoft’s xCloud game streaming is now widely available on iOS and PC - The Verge

ios.indah.link Microsoft’s xCloud, the cloud game streaming component of Xbox Game Pass Ultimate that doesn’t require a console to use, is ...

Popular Posts