RedDrop malware: Caution inflating accounts and circulating

RedDrop malware: After all these years of blogging we can be proud that we have never used terms like “Caution” in titles unless there is a good reason. RedDrop Android malware discovered it is a very serious reason.

The malware works “underground” stealing sensitive data from the infected devices (including recorded phone calls) and stores them in Cloud storage accounts.reddrop

But it does not only do that…

RedDrop works like an eavesdropping spyware, collecting information from the device, but also audio recordings from the victim's environment, along with of course all the data included on the device: photos, contacts, notes, saved Wi-Fi and nearby hotspots.

Researchers from the security company Wandera, who revealed it, refer to it as "one of the most advanced malware for Android". When RedDrop is installed no one realizes that their device is infected until they get the first bill…

Malware sends secret SMS messages to a service that charges them, in addition to all of the spyware activities mentioned above. The security company reports that malicious software is so smart that immediately after sending an SMS, it takes care to hide all the evidence of the messages that have been sent.

In total, 53 applications used to distribute malware have been discovered.
RedDrop distributes these games: Space Game Free, Video Blocker, Cosmos FM, Plus Italy, Paint It Hot Tone and Ninja Slice. None of these apps comes from the official Google Play Store, but from Third Party Stores.

However, to direct the user to the malware the researchers found that the scammers use a complex network containing over 3.000 που συνδέονται μεταξύ τους σε μια προσπάθεια να παρακάμψουν και να αποτρέψουν τις τεχνικές ανίχνευσης για να αυξήσουν τις πιθανότητες να εγκατασταθεί το κακόβουλο λογισμικό με επιτυχία σε κάποια συσκευή.

The initial download is simply a dropper, which when opened and run, will connect to a command and control (C&C) server to download additional files.

When installed spyware starts collecting the data mentioned above and saves it to Dropbox or Google Drive. At the same time it starts to use SMS sending.

The combination of these actions is extremely destructive, both for the victim's privacy and for his financial situation.

It is currently unknown what exactly the RedDrop team's goal is (besides the obvious financial gain), but their interest in stealing data and audio recordings from the infected devices suggests an interest in espionage. As it seems, the group also has enough human resources that are capable of developing many applications and also maintaining advanced malicious software.the.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).