Trending...
- Friendly Pro Services Helps Metro Detroit Homeowners Prepare for Changing Seasons, Power Outages and Winter Weather
- Sky Quarry Restarts Nevada's Only Crude Oil Refinery — A Major New Chapter Begins in This Highly Lucrative sector for N A S D A Q: SKYQ
- Radio Drive's New Album Walk With Me Delivers Two GRAMMY® Submissions Across Rock and Alternative Categories
Threat actors exploit consumer trust in legitimate government apps to plant malicious packages
AMSTERDAM - Michimich -- EclecticIQ, the global provider of cyber threat intelligence (CTI) technology solutions, has teamed up with fraud and cybercrime prevention experts at ThreatFabric to publish the findings of an investigation into instances of threat actors actively pushing malicious Android packages disguised as legitimate contact tracing applications.
Key analysis points by ThreatFabric and EclecticIQ reveal that:
The findings of the report suggest that threat actors will almost certainly continue to use commodity and open source-based malware disguised as legitimate contact tracing applications for financial gain. The low barrier to entry provided by these tools and the continued rollout of contact tracing applications by nations, presents continued financial opportunity for cybercriminals into the near future. Malicious actors have shown their willingness to exploit the current pandemic by targeting legitimate contact tracing applications consistently in recent months. Samples analyzed by EclecticIQ and ThreatFabric researchers had an earliest estimated build time of April 12th, 2020 with the latest being June 23rd, 2020.
More on Michimich.com
Peter Ferguson, Cyber Threat Intelligence Specialist at EclecticIQ's Fusion Center commented:
"Users should never download contact tracing android applications from links sent to them or from third party stores. If they are interested in downloading their nation's contact tracing application, they should use the official site or the Google Play Store."
Gaetan van Diemen, General Manager at ThreatFabric commented:
"Threat actors have become very efficient in tricking users into downloading and installing a phenomenal variety of malicious apps on their mobile devices. To avoid fraud and brand or reputation damage, we strongly recommend app developers and online service providers to adapt their security strategy based on the factual evolution of the mobile threat landscape."
Additional Resources:
About EclecticIQ
EclecticIQ enables intelligence-powered cybersecurity for government organizations and commercial enterprises. We develop analyst-centric products and services that align our clients' cyber security focus with their threat reality. The result is intelligence-led security, improved detection and prevention, and cost-efficient security investments.
Our solutions are built specifically for analysts across all intelligence-led security practices such as threat investigation and threat hunting, as well as incident response efforts. We tightly integrate our solutions with our customers' IT security controls and systems. EclecticIQ operates globally with offices in Europe, the United Kingdom and North America, and via certified value-add partners.
More on Michimich.com
Learn more at www.eclecticiq.com
About ThreatFabric
ThreatFabric helps financial institutions protect their online services, stop fraud and enhance customer experience. Powered by threat intelligence, ThreatFabric's solutions offer a holistic approach to risk detection and fraud prevention. MTI (Mobile Threat Intelligence) provides global visibility and context on the mobile banking threat landscape. It is the threat intelligence solution to use to protect personal data, customers and brand from financially motivated threat actors. It includes the strategic overview of threats and context as well as all relevant technical indicators. CSD (Client Side detection) provides the answer to the constantly-evolving fraud landscape and regulatory challenges. An omnichannel solution that empowers financial institutions to pro-actively detecting known and unknown threats to mitigate fraud and build trust across their online services.
Learn more at www.threatfabric.com
Key analysis points by ThreatFabric and EclecticIQ reveal that:
- Threat actors have been disguising Android packages as legitimate government-backed contact tracing applications for financial gain.
- There is evidence to suggest that actors have used repackaged commodity and open-source malware to lower the investment required in the observed campaigns.
- Third-party port forwarding, and secure tunneling services have probably been used to provide anonymization to command and control (C2) infrastructure.
- The Android packages were probably delivered through links pointing to phishing pages.
The findings of the report suggest that threat actors will almost certainly continue to use commodity and open source-based malware disguised as legitimate contact tracing applications for financial gain. The low barrier to entry provided by these tools and the continued rollout of contact tracing applications by nations, presents continued financial opportunity for cybercriminals into the near future. Malicious actors have shown their willingness to exploit the current pandemic by targeting legitimate contact tracing applications consistently in recent months. Samples analyzed by EclecticIQ and ThreatFabric researchers had an earliest estimated build time of April 12th, 2020 with the latest being June 23rd, 2020.
More on Michimich.com
- Dr. Jay Johannigman Returns to Cincinnati Following 46 Years of Military Service
- Allstream Energy Partners, SEO Experts in Oil and Gas, Awarded Gas Processing OEM Agreement
- Growth Story Expands: $54.6M Contract, $30M Revenue Run Rate, 800+ Customers, 50+ Patents & New AI Cybersecurity Products for Cycurion, Inc $CYCU
- Sky Quarry Restarts Nevada's Only Crude Oil Refinery — A Major New Chapter Begins in This Highly Lucrative sector for N A S D A Q: SKYQ
- Nutriband Inc. (N A S D A Q: NTRB) Breaks Into Uncharted Territory: 52-Week High Eclipsed as Shares Surge 22% —AVERSA™ Puts Investors on High Alert
Peter Ferguson, Cyber Threat Intelligence Specialist at EclecticIQ's Fusion Center commented:
"Users should never download contact tracing android applications from links sent to them or from third party stores. If they are interested in downloading their nation's contact tracing application, they should use the official site or the Google Play Store."
Gaetan van Diemen, General Manager at ThreatFabric commented:
"Threat actors have become very efficient in tricking users into downloading and installing a phenomenal variety of malicious apps on their mobile devices. To avoid fraud and brand or reputation damage, we strongly recommend app developers and online service providers to adapt their security strategy based on the factual evolution of the mobile threat landscape."
Additional Resources:
- Read full report here
About EclecticIQ
EclecticIQ enables intelligence-powered cybersecurity for government organizations and commercial enterprises. We develop analyst-centric products and services that align our clients' cyber security focus with their threat reality. The result is intelligence-led security, improved detection and prevention, and cost-efficient security investments.
Our solutions are built specifically for analysts across all intelligence-led security practices such as threat investigation and threat hunting, as well as incident response efforts. We tightly integrate our solutions with our customers' IT security controls and systems. EclecticIQ operates globally with offices in Europe, the United Kingdom and North America, and via certified value-add partners.
More on Michimich.com
- Jacqui Condon Selected to Workers' Compensation Panels for Three Professional Athlete Associations
- New Metallized PE Film from Pregis Brings Recyclability to High-Barrier Food Packaging at Pack Expo International in Chicago
- Golden Limousine International Partner Trey McKenney
- Transformational $104 Million Musculoskeletal Healthcare Opportunity as Expansion Strategy Accelerates for Cardiff Lexington Corp (Stock Symbol: CDIX)
- PropAccount.com Launches Marketing Hub Within PropGenie, Giving Prop Firm Operators an Automated Marketing Team
Learn more at www.eclecticiq.com
About ThreatFabric
ThreatFabric helps financial institutions protect their online services, stop fraud and enhance customer experience. Powered by threat intelligence, ThreatFabric's solutions offer a holistic approach to risk detection and fraud prevention. MTI (Mobile Threat Intelligence) provides global visibility and context on the mobile banking threat landscape. It is the threat intelligence solution to use to protect personal data, customers and brand from financially motivated threat actors. It includes the strategic overview of threats and context as well as all relevant technical indicators. CSD (Client Side detection) provides the answer to the constantly-evolving fraud landscape and regulatory challenges. An omnichannel solution that empowers financial institutions to pro-actively detecting known and unknown threats to mitigate fraud and build trust across their online services.
Learn more at www.threatfabric.com
Source: EclecticIQ
0 Comments
Latest on Michimich.com
- Solid Earth's new "Welcome to Real Estate" campaign introduces RealtyID™: Know Before Your Open the Door
- Radio Drive's New Album Walk With Me Delivers Two GRAMMY® Submissions Across Rock and Alternative Categories
- Kaplan Morrell and Attorney Jacqui Condon Selected to Represent Professional Women's Soccer Players in Workers' Compensation Matters
- ClearSight Therapeutics Receives NIH SBIR Phase I Award for Conjunctivitis and EKC Research
- Lunai Bioworks (N A S D A Q: LNAI) Takes Parkinson's Discovery to the Next Level With Exclusive Tanaist Agreement
- Revenue Optics Names Prat Patibandla Director of Growth Marketing
- CIMdata to Host Free Educational Webinar on Navigating PLM End-of-Life
- Independent Autopsies Are Changing Civil Cases: Kansas City Forensic Explains Why Families Are Seeking Second Opinions
- Harborside Senior Living Announces New Partnership With Huron Valley PACE
- JEGS Launches Transformed Digital Commerce Platform Powered by PhaseZero
- Subject matter experts: Present your ideas at IISE Annual Conference 2027 in Louisville
- Cummings Graduate Institute Celebrates New Doctor of Behavioral Health Graduates
- Visit London Appoints The SEO Works for AI-First Search Strategy
- Inglewood Associates and Gordon Brothers Provide Update on Sale Process for 925 Euclid Avenue in Cleveland
- Century Fasteners Corp. Exhibiting at the 2026 International Fastener Expo
- Las Vegas Attorney Thomas Boley Publishes Free Plain-English Guide to 100 Nevada Criminal Laws, in English and Spanish
- Bank Statement Loans Up to $30 Million: Lendmire Announces High-Net-Worth Financing
- Total Detail: Empty Your Vehicle Before Your Detailing Appointment for Best Results
- LaChance Brothers Excavating Encourages Homeowners to Prepare Septic Systems Before Winter Arrives
- NYC Big Book Award Celebrates 10th Anniversary with Announcement of 2026 Winners