Saturday 28 January 2017

Fake Netflix app takes access of users' android devices


Security researchers at Zscaler security have recently found a fake Netflix app that is installing a Remote Access Trojan (RAT) variant onto victims’ devices.

Depending on the popularity of applications is not a new technique, with the fake Super Mario Run games on Android have recently used the same trick to inject the DroidJack and Marcher Trojans in users' android devices. It seems that the attackers now decided to use the same technique and get the control of Netflix users' devices who are looking to stream full movies and TV programs on their mobile devices.

In the place of a video streaming app,  the attackers, however, used a RAT that can take advantage of users device in many ways, like listening to their live conversations by using the microphone, executing random commands, sending files to command and control (C&C) server, viewing contacts, recording screen captures, and reading SMS messages.

This fake Netflix app is supposedly created by using an updated version of  SpyNote RAT builder, which was leaked online last year, Zscaler says.
Once it is installed, the app displays the icon of legitimate Netflix app on Google Play, but it should by no means be mistaken for the real one.When user clicks on icon for the first time it then disappears from the home screen and nothing else seems to be happening, a trick that is commonly used by mobile malware. But in the background, the malware starts its onslaught of attacks.
The SpyNote RAT was found to be using a free DNS service for C&C communication, and also to leverage Services, Activities components and Broadcast Receivers, of Android platform to remain up and running on users’ infected device.

“Services can perform long-running operations in the background and does not need a user interface. Broadcast Receivers are Android components that can register themselves for particular events. Activities are key building blocks, central to an app’s navigation, for example,” Zscaler researchers note.

1 comment:

  1. CONTACT: onlineghosthacker247 @gmail. com
    -Find Out If Your Husband/Wife or Boyfriend/Girlfriend Is Cheating On You
    -Let them Help You Hack Any Website Or Database
    -Hack Into Any University Portal; To Change Your Grades Or Upgrade Any Personal Information/Examination Questions
    -Hack Email; Mobile Phones; Whatsapp; Text Messages; Call Logs; Facebook And Other Social Media Accounts
    -And All Related Services
    - let them help you in recovery any lost fund scam from you
    onlineghosthacker Will Get The Job Done For You
    onlineghosthacker247 @gmail. com
    TESTED AND TRUSTED!

    ReplyDelete

Thanks for reading this article.
Please comment your reviews..This will help us improve.

Popular Posts