Story image

Avoidable mistakes lead to iOS cryptomining attacks

Just five months after Kaspersky Lab’s first report on the DNS hijacking operation to infect Android smartphones in Asia, the attack dubbed ‘Roaming Mantis’ remains highly active, exploring new tricks and techniques to extend its reach. Close monitoring by Kaspersky Lab experts discovered Roaming Mantis attempting to web mine iOS devices used for legitimate crypto mining.

The malware banked on the popular CoinHive miner, the tool it first used to infect PCs. Malicious cryptocurrency mining refers to hackers infecting a crypto mining platform to mine cryptocurrency from unaware victims. Researchers also noticed that the hackers have adopted a trial and error approach to testing which technique would get them more money faster. For instance, the attacker modified the infected landing page of the malware, alternately using an Apple phishing site and a web coin-mining page.

Roaming Mantis has also boosted its attack and evasion tools. The group initially hijacked DNS systems of rogue Wi-Fi routers to infect Android users in Japan, Korea, India, and Bangladesh with Trojanized applications named facebook.apk and chrome.apk. The latest updates reveal that facebook.apk has been changed to sagawa.apk and has been spread via a rented SMS message spoofing delivery service.

This technique was first used last year by another cybergang. Kaspersky Lab also uncovered that the attacker spreads its malware via Prezi, cloud-based presentation software that allows free user accounts, making it harder for security products to detect phishing or malicious activities as this site is considered legitimate. In addition, the redirected SCAM content shows that Roaming Mantis uses templates, which suggests that Prezi is an established delivery system for malicious content, too.

Aside from the updated tools and techniques, researchers at Kaspersky Lab spotted careless mistakes committed by the hacking group as they try to dabble in additional types of attacks as fast as possible. Roaming Mantis, also known as MoqHao and XLoader, was launched in four languages and in two months quickly added two dozen more, including Asian languages --- Bengali, both traditional and simplified Chinese, Hindi, Indonesian, Japanese, Korean, Malay, Tagalog, Thai, and Vietnamese.

After this update, researchers detected mixed-ups in the language environment. For instance, Japanese users will get a pop-up message written in Korean. The group also used HTML instead of URL to redirect users to their malicious content, contrary to how Prezi as a delivery system really works.

As a result, the tweaked landing page was not able to infect its target victims. To protect your devices against Roaming Mantis attacks, Kaspersky Lab suggests users do the following:

1. Check your router’s settings.

2. Change the default login and password for admin of your devices, especially when used in crypto mining.

3. Use robust security solutions for all your devices. 4. Do not allow “Install unknown apps.”

SecOps: Clear opportunities for powerful collaboration
If there’s one thing security and IT ops professionals should do this year, the words ‘team up’ should be top priority.
Interview: Culture and cloud - the battle for cybersecurity
ESET CTO Juraj Malcho talks about the importance of culture in a cybersecurity strategy and the challenges and benefits of a world in the cloud.
Enterprise cloud deployments being exploited by cybercriminals
A new report has revealed a concerning number of enterprises still believe security is the responsibility of the cloud service provider.
Ping Identity Platform updated with new CX and IT automation
The new versions improve the user and administrative experience, while also aiming to meet enterprise needs to operate quickly and purposefully.
Venafi and nCipher Security partner on machine identity protection
Cryptographic keys serve as machine identities and are the foundation of enterprise information technology systems.
Machine learning is a tool and the bad guys are using it
KPMG NZ’s CIO and ESET’s CTO spoke at a recent cybersecurity conference about how machine learning and data analytics are not to be feared, but used.
Seagate: Data trends, opportunities, and challenges at the edge
The development of edge technology and the rise of big data have brought many opportunities for data infrastructure companies to the fore.
Popular Android apps track users and violate Google's policies
Google has reportedly taken action against some of the violators.