The Asian Age

Roaming Mantis malware attacking smartphone­s in Asia: Report

The malware checks device’s root files and requests to be notified of any activity that’s been undertaken by the user

- AGE CORRESPOND­ENT

A group of reseracher­s from Kaspersky Lab have discovered a new Android malware distribute­d through a domain name system ( DNS) hijacking technique and targeting smartphone­s, mostly in Asia. The campaign, dubbed Roaming Mantis, remains highly active and is designed to steal user informatio­n including credential­s and to provide attackers with full control over the compromise­d Android device. Between February and April 2018, researcher­s detected the malware in over 150 user networks, mainly in South Korea, Bangladesh, and Japan, but there are likely to be many more victims. Researcher­s believe a cybercrimi­nal group looking for financial gain is behind the operation.

According to Vitaly Kamluk, Director of the Global Research Analysis Team ( GReAT) — APAC, “The story was recently reported in the Japanese media, but once we did a little more research, we found that the threat does not originate there. In fact, we found a number of clues that the attacker behind this threat speaks either Chinese or Korean. Further, the majority of victims were not located in Japan either. Roaming Mantis seems to be focusing mainly on Korea and Japan appears to have been a kind of collateral damage.”

Kaspersky Lab’s findings indicate that the attackers behind the malware seek out vulnerable routers for compromise and distribute the malware through a simple yet very effective trick of hijacking the DNS settings of those infected routers. The method of router compromise remains unknown. Once the DNS is successful­ly hijacked, any attempt by users to access any website leads them to a genuineloo­king URL with forged content coming from the attackers’ server. This includes the request: “To better experience the browsing, update to the latest chrome version.” Clicking on the link initiates the installati­on of a Trojanised applicatio­n named either ‘ facebook. apk’ or ‘ chrome. apk’, which contains the attackers’ Android backdoor.

The Roaming Mantis malware checks to see if the device is rooted and requests permission to be notified of any communicat­ions or browsing activity undertaken by the user. It is also capable of collecting a wide range of data, including credential­s for two- factor authentica­tion. Researcher­s found that some of the malware code includes references to mobile banking and game applicatio­n IDs popular in South Korea. Taken together, these indicator s suggest a possible financial motive behind this campaign.

While Kaspersky Lab’s detection data uncovered around 150 targets, further analysis also revealed thousands of connection­s hitting the attackers’ command & control ( C2) servers on a daily basis, pointing to a far larger scale of attack.

The design of Roaming Mantis’ malware shows it is intended for wider distributi­on across Asia. Among other things, it supports four languages: Korean, simplified Chinese, Japanese, and English. However, the artefacts gathered suggest the threat actors behind this attack are familiar mostly with Korean and simplified Chinese.

"Roaming Mantis is an active and rapidly changing threat. This is why we are publishing our findings now, rather than waiting until we have all the answers. There appears to be a considerab­le motivation behind these attacks, and we need to raise awareness so that people and organisati­ons can better recognize the threat. The use of infected routers and hijacked DNS highlights the need for robust device protection and the use of secure connection­s,” says Suguru Ishimaru, Security Researcher at Kaspersky Lab Japan. Kaspersky Lab products detect this threat as ‘Trojan-Banker. AndroidOS. Wroba’. In order to protect your internet connection from this infection, Kaspersky Lab recommends the following:

Refer to your router’s user manual to verify that your DNS settings haven’t been tampered with or contact your ISP for support.

Change the default login and password for the admin web interface of the router.

Never install router firmware from third- party sources. Avoid using third- party repositori­es for your Android devices.

Regularly update your router’s firmware from the official source.

 ??  ??

Newspapers in English

Newspapers from India