Roaming Mantis Amplifies Smishing Campaign with OS-Specific Android Malware
ID: 1f504e02-0235-535e-b674-0f5b9a750c60
STIX ID: report--1f504e02-0235-535e-b674-0f5b9a750c60
Feed Name: McAfee Labs Blog
McAfee Mobile Research reports that the Roaming Mantis smishing campaign has targeted Asian Android users (notably Japan) with phishing SMS that lead to OS-specific fake apps (fake Chrome for Android 9 and earlier, fake Google Play for Android 10+) which install SmsSpy and related malware to exfiltrate SMS messages and contacts; the report describes infection flow, C2/update mechanisms (including hidden C2 in online documents), supported remote commands, and provides extensive IoCs (C2 IPs, update links, phishing domains, and sample hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
