RedDrop malware: After so many years of blogging we can be proud that we have never used terms like "Caution" in titles unless there is a good reason. The recently discovered RedDrop malware for Android is a very serious reason.
Malware works "underground" steals sensitive data from infected devices (including recorded phone calls) and stores them in Cloud storage accounts.
But it does not only do that…
RedDrop acts as a spyware spyware, collecting information from the device, as well as recording from the victim's environment, of course with all the data included in the device: photos, contacts, notes, stored Wi-Fi networks and nearby hotspots.
Researchers from the security company Wandera, who revealed it, refer to it as "one of the most advanced malware for Android". When RedDrop is installed no one realizes that their device is infected until they get the first bill…
Malware sends secret SMS messages to a service that charges them, in addition to all of the spyware activities mentioned above. The security company reports that malicious software is so smart that immediately after sending an SMS, it takes care to hide all the evidence of the messages that have been sent.
In total, 53 apps used to distribute the malware have been discovered software.
Στις εφαρμογές αυτές που διανέμουν το RedDrop συμπεριλαμβάνονται οι: Space Game Free, Video Blocker, Cosmos FM, Plus Italy, Paint It Hot Tone και το Ninja Slice. Καμία από αυτές τις εφαρμογές δεν προέρχεται από το επίσημο Google Play Store, αλλά από Stores third parties.
However, in order to direct the user to malware, the researchers found that scammers use a complex network that contains over 3.000 domains linked together in an effort to bypass and prevent detection techniques to increase the chances of malware software successfully on a device.
The initial download is simply a dropper, which when opened and run, will connect to a command and control (C&C) server to download additional files.
When the spyware is installed it starts collecting the data we mentioned above and saves it to Dropbox or Google Drive. At the same time, it also starts using SMS sending.
The combination of actions of these is extremely destructive, both for the victim's privacy and for his financial situation.
Currently, it is not known exactly what the RedDrop team is (except for obvious financial gain), but their interest in data theft and sound recordings from infected devices indicates interest in espionage. As the team seems to have enough human resources that is capable of deploying too many applications, it also maintains sophisticated malware.